Latest CVE Feed
-
9.8
CRITICALCVE-2023-5034
A vulnerability classified as problematic was found in SourceCodester My Food Recipe 1.0. This vulnerability affects unknown code of the file index.php of the component Image Upload Handler. The manipulation leads to unrestricted upload. The attack can be... Read more
- Published: Sep. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-50372
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
9.8
CRITICALCVE-2022-28115
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.... Read more
Affected Products : online_sports_complex_booking- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8914
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.... Read more
Affected Products : media_server- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-4150
IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 17... Read more
Affected Products : security_siteprotector_system- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43893
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.... Read more
- Published: Oct. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43902
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.... Read more
Affected Products : emsigner- Published: Nov. 14, 2023
- Modified: Jan. 08, 2025
-
9.8
CRITICALCVE-2023-0883
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-opos/index.php. The manipulation of the argument ID leads to sql injection. The attack c... Read more
- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-4207
IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP requ... Read more
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43981
Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.... Read more
Affected Products : test_site_creator- Published: Oct. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16920
v5/config/system.php in dayrui FineCms 5.2.0 has a default SYS_KEY value and does not require key regeneration for each installation, which allows remote attackers to upload arbitrary .php files via a member api swfupload action to index.php.... Read more
- Published: Nov. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-12002
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.... Read more
Affected Products : webaccess- Published: May. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-9031
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.... Read more
Affected Products : sentry_vision- Published: Mar. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0946
A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file billing/index.php?id=9. The manipulation of the argument id leads to sql inj... Read more
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44080
An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component.... Read more
Affected Products : codefever- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4410
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The expl... Read more
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36219
An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An attacker can chain multiple enclave calls to prepare a stack that contains a v... Read more
Affected Products : sgxwallet- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4407
A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4. Affected by this vulnerability is an unknown functionality of the file /portal/reports/account_statement of the component POST Request Handler. The manipulation of the argum... Read more
Affected Products : credit_lite- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0635
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104... Read more
- Published: Jun. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12481
The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonstrated by reading the "User password" field with the Drozer post.capture.clipboard module.... Read more
Affected Products : the_olive_tree_ftp_server- Published: Jun. 15, 2018
- Modified: Nov. 21, 2024