Latest CVE Feed
-
9.8
CRITICALCVE-2023-23302
The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with spe... Read more
Affected Products : connect-iq- EPSS Score: %0.33
- Published: May. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2347
A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/services/manage_service.php. The manipulation of the argument id leads to sql ... Read more
Affected Products : service_provider_management_system- EPSS Score: %0.05
- Published: Apr. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22388
There is an Integer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.... Read more
- EPSS Score: %0.24
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-26772
Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function.... Read more
Affected Products : ppgo_jobs- EPSS Score: %2.73
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-2302
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker ... Read more
Affected Products : platform_security_for_java- EPSS Score: %52.53
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24150
A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.... Read more
- EPSS Score: %1.63
- Published: Feb. 03, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2023-24052
An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.... Read more
- EPSS Score: %0.09
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24166
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.... Read more
- EPSS Score: %0.39
- Published: Jan. 26, 2023
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2023-24199
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.... Read more
Affected Products : raffle_draw_system- EPSS Score: %0.07
- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2023-24033
The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.... Read more
- EPSS Score: %0.56
- Published: Mar. 13, 2023
- Modified: Mar. 03, 2025
-
9.8
CRITICALCVE-2023-24643
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php.... Read more
Affected Products : judging_management_system- EPSS Score: %0.07
- Published: Mar. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-3934
TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, contains a vulnerability of Pre-auth SQL Injection, allowing attackers to inject a specific SQL command.... Read more
- EPSS Score: %0.38
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24775
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.... Read more
Affected Products : funadmin- EPSS Score: %58.31
- Published: Mar. 07, 2023
- Modified: Mar. 05, 2025
-
9.8
CRITICALCVE-2023-24236
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.... Read more
- EPSS Score: %2.05
- Published: Feb. 16, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-24796
Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary code via the password parameter at the /goform/sysTools and /adm/systools.asp endpoints.... Read more
- EPSS Score: %4.55
- Published: Apr. 26, 2023
- Modified: Feb. 03, 2025
-
9.8
CRITICALCVE-2023-21130
In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitati... Read more
Affected Products : android- EPSS Score: %1.06
- Published: Jun. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45069
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress ... Read more
Affected Products : video_gallery- EPSS Score: %0.21
- Published: Nov. 06, 2023
- Modified: Feb. 26, 2025
-
9.8
CRITICALCVE-2020-15323
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.... Read more
- EPSS Score: %0.51
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23274
The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a... Read more
- EPSS Score: %0.24
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-21494
Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.... Read more
- EPSS Score: %0.78
- Published: May. 04, 2023
- Modified: Nov. 21, 2024