Latest CVE Feed
-
9.8
CRITICALCVE-2022-32514
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-B... Read more
Affected Products : 5500ac2_firmware 5500nac_firmware 5500nac2_firmware 5500shac_firmware lss5500nac_firmware lss5500shac_firmware 5500ac2 5500nac 5500nac2 5500shac +2 more products- EPSS Score: %0.20
- Published: Jan. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32585
A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.... Read more
- EPSS Score: %0.18
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6373
SQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action.... Read more
Affected Products : fastball- EPSS Score: %1.14
- Published: Feb. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41232
Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is not properly esca... Read more
Affected Products : planning_poker- EPSS Score: %0.49
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6398
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.... Read more
Affected Products : event_calendar- EPSS Score: %1.41
- Published: Jan. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41679
A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue the SQL command through the /opensis/modules/grades/InputFinalGrades.php, period parameter.... Read more
Affected Products : opensis- EPSS Score: %0.56
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3327
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.... Read more
Affected Products : rdiffweb- EPSS Score: %0.11
- Published: Oct. 20, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-0224
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.45
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24144
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.... Read more
- EPSS Score: %1.45
- Published: Feb. 03, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2022-34053
The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : dr-web-engine- EPSS Score: %0.70
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5986
SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.... Read more
Affected Products : easycarscript- EPSS Score: %1.08
- Published: Jan. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-39180
College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page ... Read more
Affected Products : college_management_system- EPSS Score: %0.07
- Published: Nov. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-39266
isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code... Read more
Affected Products : isolated-vm- EPSS Score: %0.05
- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12443
BigBlueButton before 2.2.6 allows remote attackers to read arbitrary files because the presfilename (lowercase) value can be a .pdf filename while the presFilename (mixed case) value has a ../ sequence. This can be leveraged for privilege escalation via a... Read more
Affected Products : bigbluebutton- EPSS Score: %0.85
- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34577
A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.... Read more
- EPSS Score: %2.17
- Published: Jul. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-2552
Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data.... Read more
Affected Products : collected_information_export- EPSS Score: %3.33
- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15921
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restricted functionalities, such as Code Execution.... Read more
Affected Products : eframework- EPSS Score: %18.99
- Published: Jul. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34945
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.... Read more
Affected Products : pharmacy_management_system- EPSS Score: %0.25
- Published: Aug. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-21012
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edit page for Customer, Room, Currency, Room Booking Detail... Read more
Affected Products : hotel_and_lodge_booking_management_system- EPSS Score: %15.19
- Published: Oct. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-21016
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.... Read more
- EPSS Score: %3.98
- Published: Oct. 31, 2022
- Modified: May. 07, 2025