Latest CVE Feed
-
9.8
CRITICALCVE-2023-5360
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.... Read more
Affected Products : royal_elementor_addons- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-43923
Missing Authorization vulnerability in Arraytics Timetics allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Timetics: from n/a through 1.0.23.... Read more
Affected Products : wp_timetics- Published: Nov. 01, 2024
- Modified: Nov. 13, 2024
-
9.8
CRITICALCVE-2024-25825
FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 11, 2024
-
9.8
CRITICALCVE-2023-48687
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'from' parameter of the reservation.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : railway_reservation_system- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48720
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : student_result_management_system- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31956
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/manage_report.php?id=.... Read more
Affected Products : rescue_dispatch_management_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10845
A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. The manipulation of the argument id leads to sql injection. The attack can be ... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2023-52333
Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product... Read more
Affected Products : allegra- Published: Nov. 22, 2024
- Modified: Jan. 03, 2025
-
9.8
CRITICALCVE-2023-5034
A vulnerability classified as problematic was found in SourceCodester My Food Recipe 1.0. This vulnerability affects unknown code of the file index.php of the component Image Upload Handler. The manipulation leads to unrestricted upload. The attack can be... Read more
- Published: Sep. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-50372
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
9.8
CRITICALCVE-2022-28115
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.... Read more
Affected Products : online_sports_complex_booking- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8914
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.... Read more
Affected Products : media_server- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-4150
IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 17... Read more
Affected Products : security_siteprotector_system- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43893
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.... Read more
- Published: Oct. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43902
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.... Read more
Affected Products : emsigner- Published: Nov. 14, 2023
- Modified: Jan. 08, 2025
-
9.8
CRITICALCVE-2023-0883
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-opos/index.php. The manipulation of the argument ID leads to sql injection. The attack c... Read more
- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-4207
IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP requ... Read more
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43981
Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.... Read more
Affected Products : test_site_creator- Published: Oct. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16920
v5/config/system.php in dayrui FineCms 5.2.0 has a default SYS_KEY value and does not require key regeneration for each installation, which allows remote attackers to upload arbitrary .php files via a member api swfupload action to index.php.... Read more
- Published: Nov. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-12002
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.... Read more
Affected Products : webaccess- Published: May. 08, 2020
- Modified: Nov. 21, 2024