Latest CVE Feed
-
9.8
CRITICALCVE-2023-40545
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests. ... Read more
Affected Products : pingfederate- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1379
A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file addmem.php of the component POST Parameter Handler. The manipulation o... Read more
Affected Products : friendly_island_pizza_website_and_ordering_system- Published: Mar. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31897
In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.... Read more
Affected Products : webstorm- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9148
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.... Read more
Affected Products : fiyo_cms- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-22394
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware version SonicOS 7.1.1-7040. ... Read more
Affected Products : sonicos nsa_2700 nsa_3700 nsa_4700 nsa_5700 nsa_6700 nssp_10700 nssp_11700 nssp_13700 nsv_270 +12 more products- Published: Feb. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40756
User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.... Read more
Affected Products : callback_widget- Published: Aug. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40846
Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function sub_90998.... Read more
- Published: Aug. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22663
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg... Read more
- Published: Jan. 23, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2024-22751
D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.... Read more
- Published: Jan. 24, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2019-11929
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, ... Read more
Affected Products : hhvm- Published: Oct. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40945
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.... Read more
Affected Products : doctor_appointment_system- Published: Sep. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32071
The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due to improper access control. A successful exploit could allow an attacker to view and modify application data, and cause a denial of serv... Read more
Affected Products : micollab- Published: Aug. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-3245
A vulnerability was found in itsourcecode Library Management System 1.0. It has been rated as critical. Affected by this issue is the function Search of the file library_management/src/Library_Management/Forgot.java. The manipulation of the argument txtun... Read more
Affected Products : library_management_system- Published: Apr. 04, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-46347
In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http ca... Read more
Affected Products : ndk_steppingpack- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20386
ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.... Read more
- Published: Dec. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29994
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=facilities/manage_facility&id=.... Read more
Affected Products : online_sports_complex_booking_system- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20389
D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.... Read more
- Published: Dec. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30063
ftcms <=2.1 was discovered to be vulnerable to code execution attacks .... Read more
Affected Products : ftcms- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46522
TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.... Read more
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46547
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formSysLog.... Read more
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024