Latest CVE Feed
-
9.8
CRITICALCVE-2024-1032
A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /application/index/controller/Databasesource.php of the component Test Connection Handler. The manipulation l... Read more
- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18389
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username wit... Read more
Affected Products : neo4j- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49237
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.... Read more
- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2019-16699
The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution.... Read more
Affected Products : sr_freecap- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24377
The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.... Read more
Affected Products : cycle-import-check- Published: Dec. 14, 2022
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2022-2650
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.... Read more
Affected Products : wger- Published: Nov. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-4049
The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.... Read more
Affected Products : wp_user- Published: Jan. 02, 2023
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2020-10564
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.... Read more
Affected Products : wordpress_file_upload- Published: Mar. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-1002002
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/... Read more
Affected Products : webapp-builder- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16597
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Authentication is not required to exploit this vulnerability. The specific flaw exists within the pr... Read more
Affected Products : enterprise_manager- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-36580
A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.... Read more
Affected Products :- Published: Jun. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24159
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.... Read more
- Published: Feb. 14, 2023
- Modified: Mar. 20, 2025
-
9.8
CRITICALCVE-2016-10554
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3, sequelize defaulted SQLite to use MySQL backslash escaping... Read more
Affected Products : sequelize- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16716
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.... Read more
Affected Products : webaccess- Published: Jan. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0494
A vulnerability, which was classified as critical, was found in Kashipara Billing Software 1.0. This affects an unknown part of the file material_bill.php of the component HTTP POST Request Handler. The manipulation of the argument itemtypeid leads to sql... Read more
Affected Products : billing_software- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-4010
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.... Read more
Affected Products : magento- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6558
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the passwor... Read more
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-11744
A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument name leads to sql inject... Read more
Affected Products : portfolio_management_system_mca- Published: Nov. 26, 2024
- Modified: Dec. 03, 2024
-
9.8
CRITICALCVE-2019-10991
In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.... Read more
Affected Products : webaccess- Published: Jun. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18346
SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.... Read more
Affected Products : cms_web-gooroo- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024