Latest CVE Feed
-
9.8
CRITICALCVE-2020-10571
An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious data.... Read more
Affected Products : psd-tools- Published: Mar. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-42359
SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.... Read more
Affected Products : exam_form_submission_in_php_with_source_code- Published: Sep. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2452
In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than expected. This could cause subsequent heap buffer overflows.... Read more
Affected Products : threadx_netx_duo- Published: Mar. 26, 2024
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2022-31013
Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authProvider.verifyAccessKey` is an asyn... Read more
Affected Products : chat_server- Published: May. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-42491
EisBaer Scada - CWE-285: Improper Authorization... Read more
Affected Products : eisbaer_scada- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27112
pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project.php.... Read more
Affected Products : pearprojectapi- Published: Jan. 21, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-6912
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.... Read more
Affected Products : m-files_server- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12918
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].... Read more
Affected Products : kace_systems_management_appliance- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26613
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.... Read more
Affected Products : php-cms- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31122
Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If an attacker has certain details of SAML IdP metadata, and configures their own SAML on the same backend, ... Read more
- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-53351
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.... Read more
Affected Products : pipecd- Published: Mar. 21, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2020-8132
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.... Read more
Affected Products : pdf-image- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38934
Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.... Read more
- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28015
Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8... Read more
Affected Products : aterm_wg1800hp4_firmware- Published: Mar. 28, 2024
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2024-28010
Use of Hard-coded Password in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600... Read more
Affected Products : aterm_wg1800hp4_firmware- Published: Mar. 28, 2024
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2020-35326
SQL Injection vulnerability in file /inxedu/demo_inxedu_open/src/main/resources/mybatis/inxedu/website/WebsiteImagesMapper.xml in inxedu 2.0.6 via the id value.... Read more
- Published: Jan. 18, 2023
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2022-31267
Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddress%3Atext '[email protected]\n\trole = "#admin"' value.... Read more
Affected Products : gitblit- Published: May. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11141
The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at an... Read more
- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45015
Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'date' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : online_bus_booking_system- Published: Nov. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-47883
The com.altamirano.fabricio.tvbrowser TV browser application through 4.5.1 for Android is vulnerable to JavaScript code execution via an explicit intent due to an exposed MainActivity.... Read more
Affected Products : tv_browser- Published: Dec. 27, 2023
- Modified: Nov. 21, 2024