Latest CVE Feed
-
9.8
CRITICALCVE-2023-7264
The Build App Online plugin for WordPress is vulnerable to account takeover due to a weak password reset mechanism in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to reset the password of arbitrary users ... Read more
- Published: Jun. 11, 2024
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2023-0851
Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:S... Read more
Affected Products : mf1127c_firmware mf641cw_firmware mf642cdw_firmware mf644cdw_firmware mf741cdw_firmware mf743cdw_firmware mf745cdw_firmware mf746cdw_firmware lbp1127c_firmware lbp622cdw_firmware +80 more products- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7674
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` function resulting in code execution.... Read more
Affected Products : access-policy- Published: Jun. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12774
finecms in 1.9.5\controllers\member\ContentController.php allows remote attackers to operate website database... Read more
Affected Products : finecms- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-30886
School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php.... Read more
Affected Products : school_dormitory_management_system- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10516
An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all ve... Read more
- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24333
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.... Read more
- Published: Jan. 30, 2024
- Modified: Jun. 12, 2025
-
9.8
CRITICALCVE-2023-4231
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cevik Informatics Online Payment System allows SQL Injection.This issue affects Online Payment System: before 4.09. ... Read more
Affected Products : informatics_online_payment_system- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10571
An issue was discovered in psd-tools before 1.9.4. The Cython implementation of RLE decoding did not check for malicious data.... Read more
Affected Products : psd-tools- Published: Mar. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-42359
SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.... Read more
Affected Products : exam_form_submission_in_php_with_source_code- Published: Sep. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2452
In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than expected. This could cause subsequent heap buffer overflows.... Read more
Affected Products : threadx_netx_duo- Published: Mar. 26, 2024
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2022-31013
Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authProvider.verifyAccessKey` is an asyn... Read more
Affected Products : chat_server- Published: May. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-42491
EisBaer Scada - CWE-285: Improper Authorization... Read more
Affected Products : eisbaer_scada- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27112
pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project.php.... Read more
Affected Products : pearprojectapi- Published: Jan. 21, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-6912
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.... Read more
Affected Products : m-files_server- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12918
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].... Read more
Affected Products : kace_systems_management_appliance- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26613
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.... Read more
Affected Products : php-cms- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31122
Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If an attacker has certain details of SAML IdP metadata, and configures their own SAML on the same backend, ... Read more
- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-53351
Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalation of privileges.... Read more
Affected Products : pipecd- Published: Mar. 21, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2020-8132
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.... Read more
Affected Products : pdf-image- Published: Feb. 28, 2020
- Modified: Nov. 21, 2024