Latest CVE Feed
-
9.8
CRITICALCVE-2021-38189
An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> sequences and then inject arbitrary SMTP commands.... Read more
Affected Products : lettre- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13835
An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).... Read more
Affected Products : android- Published: Jun. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-20951
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.P... Read more
Affected Products : android- Published: Mar. 24, 2023
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2023-52026
TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface... Read more
- Published: Jan. 12, 2024
- Modified: Jun. 11, 2025
-
9.8
CRITICALCVE-2023-46793
Online Matrimonial Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'day' parameter in the 'register()' function of the functions.php resource does not validate the characters received and they are sent unfiltered ... Read more
Affected Products : online_matrimonial_project- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-5988
The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.... Read more
Affected Products : gs1900-10hp_firmware- Published: Dec. 31, 2015
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2022-30490
Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/update_status.php.... Read more
Affected Products : badminton_center_management_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6127
BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshake... Read more
Affected Products :- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-21057
In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitati... Read more
Affected Products : android- Published: Mar. 24, 2023
- Modified: Feb. 21, 2025
-
9.8
CRITICALCVE-2021-38423
All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buffer overflow.... Read more
Affected Products : gurumdds- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25530
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/get_find_condiction.aspx.... Read more
Affected Products : ruvaroa- Published: May. 08, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-33792
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.... Read more
- Published: May. 03, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-35156
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..... Read more
- Published: Sep. 30, 2022
- Modified: May. 20, 2025
-
9.8
CRITICALCVE-2024-2571
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage-admin.php. The manipulation leads to execution after redirect. The attack can be... Read more
- Published: Mar. 18, 2024
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2023-7017
Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an u... Read more
Affected Products :- Published: Mar. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10922
A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 and newer (All versions). An attacker with network access ... Read more
- Published: May. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-1000075
Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function... Read more
Affected Products : gravity- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-1032
A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /application/index/controller/Databasesource.php of the component Test Connection Handler. The manipulation l... Read more
- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18389
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username wit... Read more
Affected Products : neo4j- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49237
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025