Latest CVE Feed
-
9.8
CRITICALCVE-2022-40138
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only exploitable in ca... Read more
Affected Products : hermes- EPSS Score: %0.40
- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34839
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.... Read more
Affected Products : wp_oauth2_server- EPSS Score: %0.52
- Published: Jul. 22, 2022
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2023-25233
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.... Read more
- EPSS Score: %0.12
- Published: Feb. 27, 2023
- Modified: Mar. 10, 2025
-
9.8
CRITICALCVE-2022-3485
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device. ... Read more
- EPSS Score: %0.53
- Published: Dec. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25560
DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, verifying credentials, resetting them or requesting access tokens, crafts multiple JSON strings using format strings with user-controlled... Read more
Affected Products : datahub- EPSS Score: %0.16
- Published: Feb. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-21121
Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.... Read more
Affected Products : kliqqi_cms- EPSS Score: %0.30
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35490
Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around t... Read more
Affected Products : zammad- EPSS Score: %0.41
- Published: Aug. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26134
Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, ... Read more
Affected Products : git-commit-info- EPSS Score: %0.22
- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-41019
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequ... Read more
- EPSS Score: %0.33
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35741
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin b... Read more
Affected Products : cloudstack- EPSS Score: %12.16
- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20704
Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServer... Read more
Affected Products : clusterpro_x clusterpro_x_singleserversafe expresscluster_x expresscluster_x_singleserversafe- EPSS Score: %1.35
- Published: Nov. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26326
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and cal... Read more
Affected Products : buddyforms- EPSS Score: %40.15
- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-4116
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.... Read more
- EPSS Score: %22.15
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2018-5992
SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request.... Read more
Affected Products : staff_master- EPSS Score: %1.49
- Published: Feb. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-21522
An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ftl files, .bashrc files in the user directory, and finally get the permissions of the operating system.... Read more
Affected Products : halo- EPSS Score: %0.59
- Published: Sep. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-41496
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.... Read more
Affected Products : icms- EPSS Score: %0.11
- Published: Oct. 13, 2022
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2020-12870
RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.... Read more
Affected Products : pacsone_server- EPSS Score: %1.03
- Published: Sep. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36201
Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.... Read more
Affected Products : doctor\'s_appointment_system- EPSS Score: %0.20
- Published: Aug. 31, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36273
Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.... Read more
- EPSS Score: %18.36
- Published: Aug. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2682
A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/ping.cgi of the component Mini_HTTPD. The manipulation of the argument address with the input ;id;uname${I... Read more
Affected Products : caton_live- EPSS Score: %0.18
- Published: May. 12, 2023
- Modified: Jan. 24, 2025