Latest CVE Feed
-
9.8
CRITICALCVE-2015-0936
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.... Read more
- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-39405
Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.... Read more
- Published: Aug. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-1000011
Blind SQL Injection in wordpress plugin dukapress v2.5.9... Read more
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2023-1478
The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.... Read more
Affected Products : hummingbird- Published: Apr. 10, 2023
- Modified: Feb. 11, 2025
-
9.8
CRITICALCVE-2020-35674
BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-service password resets). An unauthenticated attacker is able to send a requ... Read more
Affected Products : online_invoicing_system- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1439
A vulnerability, which was classified as critical, has been found in SourceCodester Medicine Tracker System 1.0. This issue affects some unknown processing of the file medicines/view_details.php of the component GET Parameter Handler. The manipulation of ... Read more
- Published: Mar. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25124
Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple CORS-related vulnerabilities. Specifically, it allows setting the Access-Cont... Read more
Affected Products : fiber- Published: Feb. 21, 2024
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2018-11271
Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, S... Read more
Affected Products : sd855_firmware sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware qcs605_firmware sd_675_firmware +74 more products- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10046
A vulnerability has been found in lolfeedback and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The identifier of the patch is 6cf0b5f2228cd8765f734badd37910051000f2b2. It is r... Read more
Affected Products : lolfeedback- Published: Jan. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2056
A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been d... Read more
Affected Products : dedecms- Published: Apr. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51664
tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially l... Read more
Affected Products : changed-files- Published: Dec. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25140
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. This is potentially unwanted, e.g., ... Read more
- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0052
SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device... Read more
- Published: Jan. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10077
A vulnerability was found in webbuilders-group silverstripe-kapost-bridge 0.3.3. It has been declared as critical. Affected by this vulnerability is the function index/getPreview of the file code/control/KapostService.php. The manipulation leads to sql in... Read more
Affected Products : silverstripe-kapost-bridge- Published: Feb. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27162
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser... Read more
Affected Products : csz_cms- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10105
A vulnerability, which was classified as critical, was found in IP Blacklist Cloud Plugin up to 3.42 on WordPress. This affects the function valid_js_identifier of the file ip_blacklist_cloud.php of the component CSV File Import. The manipulation of the a... Read more
Affected Products : ip_blacklist_cloud- Published: May. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10070
A vulnerability was found in copperwall Twiddit. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation leads to sql injection. The identifier of the patch is 2203d4ce9810bdaccece5c48ff4888658a01a... Read more
Affected Products : twiddit- Published: Jan. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10122
A vulnerability was found in wp-donate Plugin up to 1.4 on WordPress. It has been classified as critical. This affects an unknown part of the file includes/donate-display.php. The manipulation leads to sql injection. It is possible to initiate the attack ... Read more
Affected Products : wp_donate- Published: Jul. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-35848
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.... Read more
Affected Products : cockpit- Published: Dec. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45343
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'ticket_id' parameter of the routers/ticket-message.php resource does not validate the characters received and they are sent unfiltered to the da... Read more
- Published: Nov. 02, 2023
- Modified: Nov. 21, 2024