Latest CVE Feed
-
9.8
CRITICALCVE-2022-24705
The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recvfrom into a fixed buffer that causes a buffer overflow and overwrites arbitrary memory. If the server connects with a malicious client,... Read more
Affected Products : accel-ppp- Published: Feb. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30472
Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat... Read more
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11715
Panasonic P99 devices through 2020-04-10 have Incorrect Access Control. NOTE: the vendor states that all affected products are at "End-of-software-support."... Read more
- Published: May. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32515
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form. Affe... Read more
- Published: Jan. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35491
TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.... Read more
- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35154
Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter.... Read more
Affected Products : mall_system- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-36768
A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The... Read more
Affected Products : nesp2- Published: Dec. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37809
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the speed_dir parameter in the function formSetSpeedWan.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38556
Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.... Read more
- Published: Aug. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36705
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php.... Read more
Affected Products : ingredients_stock_management_system- Published: Aug. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46262
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.... Read more
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24138
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.... Read more
- Published: Feb. 03, 2023
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2022-37071
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateOne2One.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37072
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanLinkspyMulti.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3241
The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : build_app_online- Published: Jan. 02, 2023
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2022-37095
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37091
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditWlanMacList.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37100
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33561
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.... Read more
Affected Products : time_slots_booking_calendar- Published: Aug. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37089
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditMacList.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024