Latest CVE Feed
-
9.8
CRITICALCVE-2025-27671
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Device Impersonation OVE-20230524-0015.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 01, 2025
-
9.8
CRITICALCVE-2025-28238
Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-26390
A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to... Read more
- Published: May. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-33752
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.... Read more
Affected Products : ca_automic_automation- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25347
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.... Read more
Affected Products : diaenergie- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-29385
In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.... Read more
- Published: Mar. 14, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-10658
A vulnerability classified as critical was found in Tongda OA up to 11.10. Affected by this vulnerability is an unknown functionality of the file /pda/approve_center/check_seal.php. The manipulation of the argument ID leads to sql injection. The attack ca... Read more
Affected Products : office_anywhere- Published: Nov. 01, 2024
- Modified: Nov. 04, 2024
-
9.8
CRITICALCVE-2024-32881
Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full compromise of the... Read more
Affected Products :- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10687
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, a... Read more
Affected Products : contest_gallery- Published: Nov. 05, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-10736
A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument email leads to sql injection. The atta... Read more
Affected Products : free_exam_hall_seating_management_system- Published: Nov. 03, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2022-4364
A vulnerability classified as critical has been found in Teledyne FLIR AX8 up to 1.46.16. Affected is an unknown function of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. It... Read more
- Published: Dec. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-21186
The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.... Read more
Affected Products : filesystem-template- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8581
An out-of-bounds read was addressed with improved input validation. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. A remote attacker may be able to leak memory.... Read more
Affected Products : airport_base_station_firmware- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-32011
KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal.... Read more
Affected Products :- Published: May. 01, 2025
- Modified: May. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-0470
A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been classified as critical. This affects an unknown part of the file /admin_route/inc_service_credits.php. The manipulation of the argument id leads to sql injection.... Read more
- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0121
A vulnerability in the authentication functionality of the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrator pri... Read more
- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10997
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /book_list.php. The manipulation of the argument id leads to sql injection. The attack can be... Read more
- Published: Nov. 08, 2024
- Modified: Nov. 13, 2024
-
9.8
CRITICALCVE-2024-11028
The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.5. This is due to the user impersonation feature inappropriately determining the current use... Read more
Affected Products : multimanager_wp- Published: Nov. 13, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2024-11036
The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_get_user_earnings AJAX action in all versions up to, and including... Read more
Affected Products : gamipress- Published: Nov. 19, 2024
- Modified: Feb. 04, 2025
-
9.8
CRITICALCVE-2024-11054
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload... Read more
Affected Products : simple_music_cloud_community_system- Published: Nov. 10, 2024
- Modified: Nov. 14, 2024