Latest CVE Feed
-
9.8
CRITICALCVE-2024-5063
A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injectio... Read more
Affected Products : online_course_registration_system- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24561
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start + length to overflow when the values aren't literals. If a slice() functio... Read more
Affected Products : vyper- EPSS Score: %1.19
- Published: Feb. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5084
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthen... Read more
Affected Products : hash_form- Published: May. 23, 2024
- Modified: Feb. 27, 2025
-
9.8
CRITICALCVE-2021-41609
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection... Read more
Affected Products : selectsurvey.net- EPSS Score: %3.37
- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5117
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. This affects an unknown part of the file portal.php. The manipulation of the argument username/password leads to sql injection. It is possible to... Read more
- Published: May. 20, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2019-7482
Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.... Read more
- EPSS Score: %64.58
- Published: Dec. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25089
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.... Read more
Affected Products : binisoft_windows_firewall_control- EPSS Score: %5.36
- Published: Feb. 04, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40357
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection ... Read more
Affected Products : z-blogphp- EPSS Score: %2.66
- Published: Sep. 20, 2022
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-29876
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/reports/activitylogreport, 'sortby' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all... Read more
- Published: Mar. 21, 2024
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2024-29937
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.... Read more
- Published: Apr. 11, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-2850
A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument urls leads to stack-based buffer overf... Read more
- Published: Mar. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25302
Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.... Read more
Affected Products : event_student_attendance_system- EPSS Score: %0.18
- Published: Feb. 09, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-2556
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been classified as critical. This affects an unknown part of the file attendance-info.php. The manipulation of the argument user_id leads to sql injection. It is possi... Read more
- Published: Mar. 17, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2022-40434
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.... Read more
Affected Products : softr- EPSS Score: %0.12
- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-25350
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.... Read more
Affected Products : zoo_management_system- Published: Feb. 28, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2020-19692
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.... Read more
- EPSS Score: %0.87
- Published: Apr. 04, 2023
- Modified: Aug. 12, 2025
-
9.8
CRITICALCVE-2021-41643
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.... Read more
Affected Products : church_management_system- EPSS Score: %10.73
- Published: Oct. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25722
qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.... Read more
Affected Products : qanything- EPSS Score: %0.06
- Published: Feb. 11, 2024
- Modified: Jun. 11, 2025
-
9.8
CRITICALCVE-2024-25935
Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9. ... Read more
Affected Products : registrationmagic- Published: Apr. 11, 2024
- Modified: Feb. 03, 2025
-
9.8
CRITICALCVE-2020-19853
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.... Read more
- EPSS Score: %0.26
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024