Latest CVE Feed
-
9.8
CRITICALCVE-2021-42310
Microsoft Defender for IoT Remote Code Execution Vulnerability... Read more
Affected Products : defender_for_iot- EPSS Score: %1.01
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34602
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.... Read more
- EPSS Score: %0.44
- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34159
Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality.... Read more
- EPSS Score: %0.13
- Published: Jun. 19, 2023
- Modified: Dec. 12, 2024
-
9.8
CRITICALCVE-2023-33869
Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands. ... Read more
- EPSS Score: %0.25
- Published: Jun. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21914
A heap-based buffer overflow vulnerability exists in the DecoderStream::Append functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : imagegear- EPSS Score: %1.12
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44844
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.... Read more
- EPSS Score: %1.39
- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-34951
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php.... Read more
Affected Products : pharmacy_management_system- EPSS Score: %0.25
- Published: Aug. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34575
SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFrontController::displayAjaxSendCartByEm... Read more
Affected Products : op\'art_save_cart- EPSS Score: %0.27
- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21942
An out-of-bounds write vulnerability exists in the TIFF YCbCr image parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : imagegear- EPSS Score: %1.04
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21949
An improper array index validation vulnerability exists in the JPEG-JFIF Scan header parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to an out-of-bounds write and potential code exectuion. An attacker can provide a mali... Read more
Affected Products : imagegear- EPSS Score: %0.38
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21952
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to increased privileges.... Read more
- EPSS Score: %0.46
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45527
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.... Read more
Affected Products : institutional_management_website- EPSS Score: %0.29
- Published: Feb. 08, 2023
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2022-45599
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.... Read more
- EPSS Score: %0.53
- Published: Feb. 22, 2023
- Modified: Mar. 17, 2025
-
9.8
CRITICALCVE-2022-45802
Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload some high-risk files, and may upload them to any directory, Users of the affected versions should upgrade... Read more
Affected Products : streampark- EPSS Score: %0.09
- Published: May. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34751
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.... Read more
- EPSS Score: %33.24
- Published: Jun. 14, 2023
- Modified: Jan. 02, 2025
-
9.8
CRITICALCVE-2022-45995
There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not to restart or even execute arbitrary code. It is a different vulnerability from CVE-2022-2414.... Read more
- EPSS Score: %0.12
- Published: Jan. 05, 2023
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2016-9155
The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1.73_S1; CCMD3025-DN18 prior to version v1.394_S1; CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, C... Read more
- EPSS Score: %0.92
- Published: Nov. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2022-36554
A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.... Read more
- EPSS Score: %2.73
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36558
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.... Read more
Affected Products : skybridge_mb-a110_firmware skybridge_mb-a100_firmware skybridge_mb-a100 skybridge_mb-a110- EPSS Score: %0.34
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-35885
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.... Read more
Affected Products : cloudpanel- EPSS Score: %94.12
- Published: Jun. 20, 2023
- Modified: Dec. 09, 2024