Latest CVE Feed
-
9.8
CRITICALCVE-2019-12193
H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter.... Read more
Affected Products : h3cloud_os- Published: Jul. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17137
Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might allow attackers to bypass intended access restrictions.... Read more
Affected Products : next- Published: Sep. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12698
An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible authentication bypass that could allow remote code execution.... Read more
Affected Products : webaccess- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12471
The cnb_parse_lev function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging failure to check for out-of-bounds conditions, which triggers an invalid read in the hexdump function.... Read more
Affected Products : ccn-lite- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19307
An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by sending a crafted MQTT protocol packet.... Read more
Affected Products : mongoose- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15823
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.... Read more
Affected Products : wps_hide_login- Published: Aug. 30, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-16165
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.... Read more
- Published: Jul. 30, 2020
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-50434
emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This can be triggered by a remote adversary that can send DNS requests to the emdns server. The im... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37181
72crm 9.0 has an Arbitrary file upload vulnerability.... Read more
Affected Products : wukong_crm- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4851
A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploi... Read more
Affected Products : ibos- Published: Sep. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37112
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php... Read more
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29805
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.... Read more
Affected Products : fishbowl- Published: Aug. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-32161
jizhiCMS 2.5 suffers from a File upload vulnerability.... Read more
Affected Products : jizhicms- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-19180
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php... Read more
Affected Products : yunucms- Published: Nov. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1999019
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a sim... Read more
Affected Products : chamilo_lms- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2653
A vulnerability classified as critical was found in SourceCodester Lost and Found Information System 1.0. Affected by this vulnerability is an unknown functionality of the file items/index.php. The manipulation of the argument cid leads to sql injection. ... Read more
Affected Products : lost_and_found_information_system- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29312
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpa... Read more
Affected Products : zend_framework- Published: Apr. 04, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2023-26858
SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.... Read more
Affected Products : frequently_asked_questions_page- Published: Mar. 31, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2017-17713
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp paramete... Read more
Affected Products : trape- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17413
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUBackupTa... Read more
Affected Products : netvault_backup- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024