Latest CVE Feed
-
9.8
CRITICALCVE-2023-4851
A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploi... Read more
Affected Products : ibos- Published: Sep. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37112
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php... Read more
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29805
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.... Read more
Affected Products : fishbowl- Published: Aug. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-32161
jizhiCMS 2.5 suffers from a File upload vulnerability.... Read more
Affected Products : jizhicms- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-19180
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php... Read more
Affected Products : yunucms- Published: Nov. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1999019
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a sim... Read more
Affected Products : chamilo_lms- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2653
A vulnerability classified as critical was found in SourceCodester Lost and Found Information System 1.0. Affected by this vulnerability is an unknown functionality of the file items/index.php. The manipulation of the argument cid leads to sql injection. ... Read more
Affected Products : lost_and_found_information_system- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29312
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpa... Read more
Affected Products : zend_framework- Published: Apr. 04, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2023-26858
SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.... Read more
Affected Products : frequently_asked_questions_page- Published: Mar. 31, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2017-17713
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp paramete... Read more
Affected Products : trape- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17413
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUBackupTa... Read more
Affected Products : netvault_backup- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-9335
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.... Read more
Affected Products : limit_attempts- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10283
The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order to maintain backwards compatibility, GCS and autopilot negotiate the version via the AUTOPILOT_VERSION mes... Read more
Affected Products : micro_air_vehicle_link- Published: Aug. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12498
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.... Read more
Affected Products : icms- Published: Jun. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-7131
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_employee_attendance. The manipulation of the argument empl... Read more
Affected Products : payroll_management_system- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-27845
In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated ... Read more
Affected Products : weblogic_server- Published: Jan. 27, 2017
- Modified: Aug. 13, 2025
-
9.8
CRITICALCVE-2025-40600
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.... Read more
Affected Products : sonicos nsa_2700 nsa_3700 nsa_4700 nsa_5700 nsa_6700 nssp_10700 nssp_11700 nssp_13700 tz270 +13 more products- Published: Jul. 29, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-2048
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certifica... Read more
Affected Products : vault- Published: Mar. 04, 2024
- Modified: Aug. 06, 2025
-
9.8
CRITICALCVE-2023-43091
A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.... Read more
Affected Products : gnome-maps- Published: Nov. 17, 2024
- Modified: Aug. 06, 2025