Latest CVE Feed
-
9.8
CRITICALCVE-2024-39375
TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.... Read more
- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9010
An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGate... Read more
- Published: Aug. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-40502
SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the Loginpage.aspx... Read more
- Published: Jul. 22, 2024
- Modified: May. 16, 2025
-
9.8
CRITICALCVE-2024-40524
Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application.py component.... Read more
Affected Products :- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-43956
Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1.11.34.... Read more
Affected Products : memberpress- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2023-39641
Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component PsaffiliateGetaffiliatesdetailsModuleFrontController::initContent().... Read more
Affected Products : full_affiliates- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45173
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker c... Read more
Affected Products : vdesk- Published: Apr. 14, 2023
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2023-39661
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.... Read more
Affected Products : pandasai- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39665
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.... Read more
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45276
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.... Read more
Affected Products : yjcms- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2017-15976
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.... Read more
Affected Products : zeebuddy- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-22137
A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A specially-crafted malformed file can lead to an arbitrary free. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : imagegear- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24752
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQ... Read more
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33719
Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.... Read more
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45551
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.... Read more
- Published: Mar. 03, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-30013
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.... Read more
- Published: May. 05, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2024-1268
A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely... Read more
Affected Products : restaurant_pos_system- Published: Feb. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30054
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.... Read more
- Published: May. 05, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-43519
Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6430_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware +262 more products- Published: Feb. 06, 2024
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2022-45699
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.... Read more
- Published: Feb. 10, 2023
- Modified: Jun. 17, 2025