Latest CVE Feed
-
9.8
CRITICALCVE-2022-36585
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.... Read more
- EPSS Score: %0.47
- Published: Sep. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36719
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the ok parameter at /admin/history.php.... Read more
Affected Products : library_management_system- EPSS Score: %0.32
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36708
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/bookdetails.php.... Read more
Affected Products : library_management_system- EPSS Score: %0.31
- Published: Aug. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36735
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php.... Read more
Affected Products : library_management_system- EPSS Score: %0.10
- Published: Aug. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-42038
The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.... Read more
Affected Products : d8s-ip-addresses- EPSS Score: %0.13
- Published: Oct. 11, 2022
- Modified: May. 19, 2025
-
9.8
CRITICALCVE-2022-42041
The d8s-file-system package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.... Read more
Affected Products : d8s-file-system- EPSS Score: %0.13
- Published: Oct. 11, 2022
- Modified: May. 19, 2025
-
9.8
CRITICALCVE-2022-36952
In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.... Read more
Affected Products : netbackup- EPSS Score: %0.18
- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36976
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the GroupDaoImpl class. A crafted request can trigger execution of SQL queries composed from a us... Read more
Affected Products : avalanche- EPSS Score: %2.13
- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36981
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The spe... Read more
Affected Products : avalanche- EPSS Score: %31.60
- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27757
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file.... Read more
Affected Products : perfreeblog- EPSS Score: %0.11
- Published: Mar. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27821
Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.... Read more
Affected Products : databasir- EPSS Score: %1.01
- Published: Mar. 28, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2017-6550
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.... Read more
Affected Products : infor-lawson- EPSS Score: %3.14
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-37128
In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.... Read more
- EPSS Score: %13.86
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37199
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.... Read more
Affected Products : jfinal_cms- EPSS Score: %0.23
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37204
Final CMS 5.1.0 is vulnerable to SQL Injection.... Read more
Affected Products : jfinal_cms- EPSS Score: %0.46
- Published: Sep. 20, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-37223
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.... Read more
Affected Products : jfinal_cms- EPSS Score: %0.23
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22253
Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitr... Read more
- EPSS Score: %0.62
- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22819
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.... Read more
Affected Products : mkcms- EPSS Score: %0.07
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2020-13167
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.... Read more
Affected Products : netsweeper- EPSS Score: %93.13
- Published: May. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6639
An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d.... Read more
Affected Products : mathtype- EPSS Score: %4.24
- Published: Feb. 28, 2018
- Modified: Nov. 21, 2024