Latest CVE Feed
-
9.8
CRITICALCVE-2024-7376
A vulnerability, which was classified as critical, was found in SourceCodester Simple Realtime Quiz System 1.0. Affected is an unknown function of the file /print_quiz_records.php. The manipulation of the argument id leads to sql injection. It is possible... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 02, 2024
- Modified: Aug. 09, 2024
-
9.8
CRITICALCVE-2024-7443
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Vivotek IB8367A VVTK-0100b. Affected is the function getenv of the file upload_file.cgi. The manipulation of the argument QUERY_STRING leads to command injection. It ... Read more
- Published: Aug. 03, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2023-6898
A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. The exploit has been discl... Read more
- Published: Dec. 17, 2023
- Modified: Dec. 23, 2024
-
9.8
CRITICALCVE-2024-7468
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslvpn_config_mod of the file /vpn/list_service_manage.php of the component Web Interface. The manipulation of... Read more
Affected Products : msg2300_firmware msg2300 msg2100e_firmware msg2100e msg2200_firmware msg2200 msg1200_firmware msg1200- Published: Aug. 05, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2024-7503
The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes ... Read more
- Published: Aug. 12, 2024
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2024-34935
A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.... Read more
Affected Products : complete_web-based_school_management_system- Published: May. 23, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2024-7748
A vulnerability, which was classified as critical, has been found in SourceCodester Accounts Manager App 1.0. This issue affects some unknown processing of the file /endpoint/delete-account.php. The manipulation of the argument account leads to sql inject... Read more
- Published: Aug. 13, 2024
- Modified: Nov. 22, 2024
-
9.8
CRITICALCVE-2023-34566
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.... Read more
- Published: Jun. 08, 2023
- Modified: Jan. 06, 2025
-
9.8
CRITICALCVE-2024-7911
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file /simple-online-bidding-system/bidding/index.php. The manipulation of the argument page leads to file... Read more
Affected Products : simple_online_bidding_system- Published: Aug. 18, 2024
- Modified: Aug. 19, 2024
-
9.8
CRITICALCVE-2024-7071
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection.This issue affects Brain Low-Code: before 2... Read more
Affected Products : brain_low-code- Published: Aug. 27, 2024
- Modified: Aug. 30, 2024
-
9.8
CRITICALCVE-2024-8086
A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the component Admin Login. The manipulation of the argument user_email lea... Read more
- Published: Aug. 22, 2024
- Modified: Aug. 27, 2024
-
9.8
CRITICALCVE-2024-36535
Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.... Read more
Affected Products : meshery- Published: Jul. 24, 2024
- Modified: Sep. 03, 2025
-
9.8
CRITICALCVE-2022-42166
Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.... Read more
- Published: Oct. 17, 2022
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2024-8210
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. ... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-320l dns-120_firmware dns-120 dnr-202l_firmware dnr-202l dns-315l_firmware dns-315l +30 more products- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8221
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/categories/manage_category.php. The manipulation of the argument id leads to sql inj... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8255
Delta Electronics DTN Soft version 2.0.1 and prior are vulnerable to an attacker achieving remote code execution through a deserialization of untrusted data vulnerability.... Read more
Affected Products : dtn_soft- Published: Aug. 29, 2024
- Modified: Sep. 06, 2024
-
9.8
CRITICALCVE-2024-8073
Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13.... Read more
Affected Products : web_application_firewall- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
9.8
CRITICALCVE-2024-8341
A vulnerability classified as critical was found in SourceCodester Petshop Management System 1.0. This vulnerability affects unknown code of the file /controllers/add_user.php. The manipulation of the argument avatar leads to unrestricted upload. The atta... Read more
- Published: Aug. 30, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-40482
An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : live_membership_system- Published: Aug. 12, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2023-34991
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthoriz... Read more
Affected Products : fortiwlm- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024