Latest CVE Feed
-
9.8
CRITICALCVE-2022-28993
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.... Read more
Affected Products : multi_store_inventory_management_system- EPSS Score: %0.34
- Published: May. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37354
Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.... Read more
- EPSS Score: %0.47
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37388
A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.... Read more
- EPSS Score: %3.43
- Published: Aug. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18285
SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to insufficient input validation for the login interface. A successful exploit could allow an attacker to extrac... Read more
Affected Products : cmg_suite- EPSS Score: %0.62
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11815
In Rukovoditel 2.5.2, attackers can upload arbitrary file to the server by just changing the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs without the Maintenance Mode setting.... Read more
Affected Products : rukovoditel- EPSS Score: %0.88
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37400
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.... Read more
- EPSS Score: %0.70
- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29316
Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.... Read more
Affected Products : complete_online_job_search_system- EPSS Score: %0.25
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37558
A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackers to execute arbitrary SQL commands via the host_name and service_description parameters. The vulnerability can be ... Read more
Affected Products : centreon- EPSS Score: %2.06
- Published: Aug. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3757
immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')... Read more
Affected Products : immer- EPSS Score: %0.12
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18529
ThinkPHP 3.2.4 has SQL Injection via the count parameter because the Library/Think/Db/Driver/Mysql.class.php parseKey function mishandles the key variable. NOTE: a backquote character is not required in the attack URI.... Read more
Affected Products : thinkphp- EPSS Score: %0.26
- Published: Oct. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28797
A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following... Read more
- EPSS Score: %0.63
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29600
The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.... Read more
Affected Products : oelib- EPSS Score: %0.25
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37843
The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided). The fixed versions are for Jira: 3.6.6.1, 4.0.12, 5.0.5; for Confluence 3.6... Read more
Affected Products : saml_single_sign_on- EPSS Score: %0.91
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11829
Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493e40_200722.... Read more
Affected Products : coloros- EPSS Score: %0.50
- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43084
An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.... Read more
- EPSS Score: %0.23
- Published: Mar. 24, 2022
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2022-29988
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete.... Read more
Affected Products : online_sports_complex_booking_system- EPSS Score: %0.25
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30000
Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=.... Read more
- EPSS Score: %0.25
- Published: May. 12, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2022-30047
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.... Read more
Affected Products : mcms- EPSS Score: %0.36
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24711
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently ... Read more
Affected Products : codeigniter- EPSS Score: %0.41
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38190
An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it does not ensure that the number of elements is equal to the product of the row count and column count.... Read more
Affected Products : nalgebra- EPSS Score: %0.36
- Published: Aug. 08, 2021
- Modified: Nov. 21, 2024