Latest CVE Feed
-
9.8
CRITICALCVE-2021-23448
All versions of package config-handler are vulnerable to Prototype Pollution when loading config files.... Read more
Affected Products : config-handler- EPSS Score: %0.44
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27251
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code execution.... Read more
Affected Products : factorytalk_linx- EPSS Score: %16.80
- Published: Nov. 26, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0982
The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereby user input cmdline_len is copied into a fixed buffer b->buf without any bound checks. If the server connects with a malicious client,... Read more
Affected Products : accel-ppp- EPSS Score: %0.41
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15474
In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.... Read more
Affected Products : ndpi- EPSS Score: %0.50
- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26512
CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq mess... Read more
- EPSS Score: %0.07
- Published: Jul. 17, 2023
- Modified: Jun. 25, 2025
-
9.8
CRITICALCVE-2023-4677
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the... Read more
Affected Products : pandora_fms- EPSS Score: %0.11
- Published: Nov. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15504
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) ... Read more
Affected Products : xg_firewall_firmware- EPSS Score: %0.15
- Published: Jul. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26613
An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.... Read more
- EPSS Score: %68.95
- Published: Jun. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1082
A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The manipulation of the argument username/password with the input '||1=1# leads t... Read more
Affected Products : microfinance_management_system- EPSS Score: %0.36
- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-22920
A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected ... Read more
- EPSS Score: %0.73
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15543
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.... Read more
- EPSS Score: %4.45
- Published: Jul. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27105
A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical s... Read more
- EPSS Score: %0.40
- Published: Apr. 25, 2023
- Modified: Feb. 03, 2025
-
9.8
CRITICALCVE-2020-27481
An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Param... Read more
Affected Products : good_learning_management_system- EPSS Score: %51.48
- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23086
Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.... Read more
Affected Products : mojojson- EPSS Score: %0.11
- Published: Feb. 03, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2023-23059
An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to execute arbitrary code and gain escalated privileges.... Read more
Affected Products : gv-edge_recording_manager- EPSS Score: %0.12
- Published: May. 04, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-27204
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.... Read more
Affected Products : best_pos_management_system- EPSS Score: %0.07
- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23331
Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.... Read more
Affected Products : xoffice- EPSS Score: %0.07
- Published: Jan. 24, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2023-47458
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.... Read more
Affected Products : springblade- EPSS Score: %0.92
- Published: Jan. 02, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2023-27583
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges. Version 3.1.3 h... Read more
Affected Products : panindex- EPSS Score: %0.21
- Published: Mar. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44098
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.... Read more
Affected Products : expense_management_system- EPSS Score: %0.48
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024