Latest CVE Feed
-
9.8
CRITICALCVE-2022-28495
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- EPSS Score: %0.62
- Published: Mar. 24, 2023
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2022-28436
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Hide&userid=.... Read more
Affected Products : baby_care_system- EPSS Score: %0.25
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28424
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&find=.... Read more
Affected Products : baby_care_system- EPSS Score: %0.25
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28530
Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.... Read more
Affected Products : covid-19_directory_on_vaccination_system- EPSS Score: %0.24
- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28375
Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A remote attacker on the local network can inject shell metacharacters into /... Read more
- EPSS Score: %4.39
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28412
Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package.... Read more
Affected Products : car_driving_school_management_system- EPSS Score: %0.24
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28434
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=edit&sid=2.... Read more
Affected Products : baby_care_system- EPSS Score: %0.25
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28413
Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment.... Read more
Affected Products : car_driving_school_management_system- EPSS Score: %0.24
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28331
On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.... Read more
- EPSS Score: %0.23
- Published: Jan. 31, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2022-28425
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=display&value=1&roleid=.... Read more
Affected Products : baby_care_system- EPSS Score: %0.25
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28357
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.... Read more
Affected Products : nats-server- EPSS Score: %0.23
- Published: Sep. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28410
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent.... Read more
Affected Products : simple_real_estate_portal_system- EPSS Score: %0.24
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-53944
An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2_v1.0.1481.15.02_P0. A unauthenticated remote attacker with network access can exploit a command injectio... Read more
Affected Products :- Published: Feb. 27, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2014-2323
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.... Read more
- EPSS Score: %92.42
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2022-28480
ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.... Read more
Affected Products : allmediaserver- EPSS Score: %0.41
- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28423
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=delete.... Read more
Affected Products : baby_care_system- EPSS Score: %0.25
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28373
Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of the crtcrpc JSON listener in /usr/lib/lua/luci/crtc.lua. A remote attacker on the local network can inject s... Read more
- EPSS Score: %4.39
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28321
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such con... Read more
- EPSS Score: %0.10
- Published: Sep. 19, 2022
- Modified: May. 29, 2025
-
9.8
CRITICALCVE-2022-28416
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.... Read more
Affected Products : home_owners_collection_management_system- EPSS Score: %0.25
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28524
ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.... Read more
Affected Products : ed01-cms- EPSS Score: %0.25
- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024