Latest CVE Feed
-
9.8
CRITICALCVE-2024-42572
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.... Read more
Affected Products : school_management_system- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
9.8
CRITICALCVE-2024-42637
H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.... Read more
- Published: Aug. 16, 2024
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2024-42757
Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.... Read more
Affected Products :- Published: Aug. 15, 2024
- Modified: Aug. 20, 2024
-
9.8
CRITICALCVE-2019-9874
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP P... Read more
- Actively Exploited
- Published: May. 31, 2019
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2024-46340
TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.... Read more
- Published: Dec. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-29243
Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the vpn_client_ip parameter at /apply.cgi.... Read more
- Published: Mar. 21, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-28001
Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter.... Read more
Affected Products : movie_seat_reservation- Published: Apr. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37172
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.... Read more
- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4345
The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process' function in the 'startklarDropZoneUploadProcess' class in versions up to, and including, 1.7.13. This mak... Read more
Affected Products : startklar_elmentor_addons- Published: May. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1698
The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient esca... Read more
Affected Products : notificationx- Published: Feb. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28093
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : online_sports_complex_booking_system- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-43698
Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin rights on the system.... Read more
Affected Products :- Published: Oct. 22, 2024
- Modified: Oct. 23, 2024
-
9.8
CRITICALCVE-2023-37700
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.... Read more
- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37701
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.... Read more
- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-42425
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.... Read more
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37754
PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.... Read more
Affected Products : powerjob- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10031
A vulnerability classified as critical was found in purpleparrots 491-Project. This vulnerability affects unknown code of the file update.php of the component Highscore Handler. The manipulation leads to sql injection. The name of the patch is a812a5e4cf7... Read more
Affected Products : 491-project- Published: Jan. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37794
WAYOS FBM-291W 19.09.11V was discovered to contain a command injection vulnerability via the component /upgrade_filter.asp.... Read more
- Published: Jul. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-42493
EisBaer Scada - CWE-256: Plaintext Storage of a Password... Read more
Affected Products : eisbaer_scada- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-27444
langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the __import__, __subclasses__, __builtins__, __globals__, __getattribute__, __bases__, __mro_... Read more
- Published: Feb. 26, 2024
- Modified: Jul. 14, 2025