Latest CVE Feed
-
9.8
CRITICALCVE-2024-1034
A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile of the file /application/index/controller/File.php. The manipulation leads to unrestricted upload. It is possible to initiate the atta... Read more
- EPSS Score: %0.10
- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5580
A vulnerability classified as critical has been found in SourceCodester Library System 1.0. This affects an unknown part of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to initiate the attack remotel... Read more
Affected Products : library_system- EPSS Score: %0.05
- Published: Oct. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5601
The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.... Read more
Affected Products : woocommerce_ninja_forms_product_add-ons- EPSS Score: %0.81
- Published: Nov. 06, 2023
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2021-46427
An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.... Read more
Affected Products : simple_chatbot_application- EPSS Score: %0.38
- Published: Jan. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5716
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests without permission.... Read more
Affected Products : armoury_crate- EPSS Score: %1.72
- Published: Jan. 19, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5765
Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching. ... Read more
- EPSS Score: %0.09
- Published: Nov. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5777
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is immediately deleted after the crash report transmission is finished, the private key is exposed to the public, which could result in obtaining remote control of the cra... Read more
Affected Products : easybuilder_pro- EPSS Score: %0.10
- Published: Nov. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46457
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnerability allows attackers to execute arbitrary commands via the samba_name parameter.... Read more
- EPSS Score: %7.87
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5877
The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, includi... Read more
Affected Products : affiliate-toolkit- EPSS Score: %0.34
- Published: Jan. 01, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-52030
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setOpModeCfg function.... Read more
- EPSS Score: %14.82
- Published: Jan. 11, 2024
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2024-36260
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.... Read more
- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6014
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.... Read more
Affected Products : mlflow- EPSS Score: %0.67
- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6036
The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attacker... Read more
Affected Products : web3_-_crypto_wallet_login_\&_nft_token_gating- EPSS Score: %46.58
- Published: Feb. 12, 2024
- Modified: May. 06, 2025
-
9.8
CRITICALCVE-2023-6078
An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.... Read more
Affected Products : biovia_materials_studio- EPSS Score: %0.34
- Published: Feb. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6190
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University Information Management System allows Absolute Path Traversal.This issue affects University Information Management Syst... Read more
Affected Products : university_information_management_system- EPSS Score: %0.20
- Published: Dec. 27, 2023
- Modified: Nov. 27, 2024
-
9.8
CRITICALCVE-2024-36783
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.... Read more
- Published: Jun. 03, 2024
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2023-30990
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.... Read more
- EPSS Score: %0.21
- Published: Jul. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6342
Tyler Technologies Court Case Management Plus allows a remote attacker to authenticate as any user by manipulating at least the 'CmWebSearchPfp/Login.aspx?xyzldk=' and 'payforprint_CM/Redirector.ashx?userid=' parameters. The vulnerable "pay for print" fe... Read more
Affected Products : court_case_management_plus- EPSS Score: %0.97
- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-4861
The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended.... Read more
Affected Products : secret_server- EPSS Score: %0.50
- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6416
A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signup2.php in the emailadd parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially cr... Read more
Affected Products : voovi- EPSS Score: %0.18
- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024