Latest CVE Feed
-
9.8
CRITICALCVE-2022-40872
An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode.... Read more
Affected Products : simple_e-learning_system- EPSS Score: %0.08
- Published: Oct. 07, 2022
- Modified: May. 20, 2025
-
9.8
CRITICALCVE-2024-2813
A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-ba... Read more
- Published: Mar. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-55509
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.... Read more
Affected Products : complaint_management_system- Published: Dec. 20, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-55586
Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 12, 2024
-
9.8
CRITICALCVE-2024-3347
A vulnerability was found in SourceCodester Airline Ticket Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file activate_jet_details_form_handler.php. The manipulation of the argument jet_id leads t... Read more
Affected Products : airline_ticket_reservation_system- Published: Apr. 05, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2024-28441
File Upload vulnerability in magicflue v.7.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the messageid parameter of the mail/mailupdate.jsp endpoint.... Read more
Affected Products : magicflue- Published: Mar. 22, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-3356
A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/mod_settings/controller.php?action=add. The manipulation o... Read more
Affected Products : aplaya_beach_resort_online_reservation_system- Published: Apr. 05, 2024
- Modified: Feb. 11, 2025
-
9.8
CRITICALCVE-2024-33567
Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.... Read more
Affected Products : barcode_scanner_and_inventory_manager- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-33835
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.... Read more
- Published: May. 01, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2023-3238
A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown processing of the file /admin/read.php?mudi=getSignal. The manipulation of the argument signalUrl leads to server-side request forgery. ... Read more
Affected Products : otcms- EPSS Score: %0.06
- Published: Jun. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31989
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=user/manage_user&id=.... Read more
Affected Products : badminton_center_management_system- EPSS Score: %0.25
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2934
A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-todo.php. The manipulation of the argument list leads to sql injectio... Read more
Affected Products : todo_list_in_kanban_board- Published: Mar. 27, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2024-34256
OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.... Read more
Affected Products : ofcms- Published: May. 14, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2022-41002
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequ... Read more
- EPSS Score: %0.45
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-29873
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/businessunits/format/html, 'bunitname' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and ex... Read more
- Published: Mar. 21, 2024
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2024-30221
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart.This issue affects Sunshine Photo Cart: from n/a through 3.1.1. ... Read more
Affected Products : sunshine_photo_cart- Published: Mar. 28, 2024
- Modified: Apr. 08, 2025
-
9.8
CRITICALCVE-2024-30622
Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the mitInterface parameter from fromAddressNat function.... Read more
- Published: Mar. 29, 2024
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2024-35387
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.... Read more
- Published: May. 24, 2024
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2021-22566
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged by an attacker to bypass executability restrictions of kernel-mode pages fr... Read more
Affected Products : fuchsia- EPSS Score: %0.01
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46452
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via the tomography_ping_address, tomography... Read more
- EPSS Score: %5.86
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024