Latest CVE Feed
-
9.8
CRITICALCVE-2024-2927
A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown function of the file Details.php of the component Login Page. The manipulation of the argument id leads to sql injection. It is possible... Read more
Affected Products : mobile_shop- Published: Mar. 26, 2024
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2022-41004
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequ... Read more
- EPSS Score: %0.45
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-41018
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequ... Read more
- EPSS Score: %0.33
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-29870
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability ... Read more
- Published: Mar. 21, 2024
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2024-29836
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full access of the site.... Read more
Affected Products :- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5732
A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects unknown code of the component Proxy Port. The manipulation leads to improper authentication. The attack can be initiated remotely. The... Read more
Affected Products : clash- Published: Jun. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5340
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.... Read more
Affected Products : five_star_restaurant_menu- EPSS Score: %0.98
- Published: Nov. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1360
The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change server configuration settings.... Read more
Affected Products : cnmaestro- EPSS Score: %1.24
- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-34943
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.... Read more
- Published: May. 14, 2024
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2024-30620
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.... Read more
- Published: Apr. 02, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2024-30508
Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2. ... Read more
Affected Products : wp_hotel_booking- Published: Mar. 29, 2024
- Modified: Feb. 11, 2025
-
9.8
CRITICALCVE-2024-30923
SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering... Read more
Affected Products : derbynet- Published: Apr. 18, 2024
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2024-5826
In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack of a sandbox when executing LLM-generated code, allowing an attacker to manipulate the code execut... Read more
Affected Products :- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31218
Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in versions 0.9.0 and earlier are subject to Missing Authentication for Critical Function vulnerability. This vulnerability allows an unau... Read more
Affected Products :- Published: Apr. 05, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23170
SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environment that uses the Okta SSO integration might be vulnerable. An unauthenticated attacker could exploit the XXE vulnerability by sending ... Read more
Affected Products : okta_sso- EPSS Score: %0.36
- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31352
Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.... Read more
- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41661
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP web... Read more
Affected Products : church_management_system- EPSS Score: %0.49
- Published: Jun. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28461
Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited... Read more
- Actively Exploited
- EPSS Score: %89.76
- Published: Mar. 15, 2023
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2023-5373
A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected is the function register of the file Master.php. The manipulation of the argument email leads to sql injection. It is possible to launch... Read more
Affected Products : online_computer_and_laptop_store- EPSS Score: %0.04
- Published: Oct. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6065
A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument user_email leads to sql injection. The attack ma... Read more
- Published: Jun. 17, 2024
- Modified: Nov. 21, 2024