Latest CVE Feed
-
9.8
CRITICALCVE-2023-39453
A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.... Read more
Affected Products : imagegear- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34800
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.... Read more
- Published: Jun. 15, 2023
- Modified: Dec. 16, 2024
-
9.8
CRITICALCVE-2024-40393
Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.... Read more
Affected Products : online_clinic_management_system- Published: Jul. 16, 2024
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2024-1228
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before vers... Read more
Affected Products : przychodnia- Published: Jun. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39375
TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.... Read more
- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9010
An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGate... Read more
- Published: Aug. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-40502
SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the Loginpage.aspx... Read more
- Published: Jul. 22, 2024
- Modified: May. 16, 2025
-
9.8
CRITICALCVE-2024-40524
Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application.py component.... Read more
Affected Products :- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-43956
Missing Authorization vulnerability in Caseproof, LLC Memberpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Memberpress: from n/a through 1.11.34.... Read more
Affected Products : memberpress- Published: Nov. 01, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2023-39641
Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component PsaffiliateGetaffiliatesdetailsModuleFrontController::initContent().... Read more
Affected Products : full_affiliates- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45173
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker c... Read more
Affected Products : vdesk- Published: Apr. 14, 2023
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2023-39661
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.... Read more
Affected Products : pandasai- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39665
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.... Read more
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45276
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.... Read more
Affected Products : yjcms- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2017-15976
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.... Read more
Affected Products : zeebuddy- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-22137
A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A specially-crafted malformed file can lead to an arbitrary free. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : imagegear- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24752
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQ... Read more
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33719
Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.... Read more
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45551
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.... Read more
- Published: Mar. 03, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-30013
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.... Read more
- Published: May. 05, 2023
- Modified: Jan. 29, 2025