Latest CVE Feed
-
9.8
CRITICALCVE-2024-6116
A vulnerability, which was classified as critical, has been found in itsourcecode Simple Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file edit_room.php. The manipulation of the argument photo leads to u... Read more
Affected Products : simple_online_hotel_reservation_system- Published: Jun. 18, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32674
Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow.... Read more
Affected Products : pc_hardware_diagnostics- EPSS Score: %0.64
- Published: Jun. 12, 2023
- Modified: Jan. 03, 2025
-
9.8
CRITICALCVE-2024-6440
A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Master.php?f=delete_category. The manipulation of the argument id leads to s... Read more
Affected Products : home_owners_collection_management_system- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3418
A vulnerability, which was classified as critical, was found in SourceCodester Online Courseware 1.0. Affected is an unknown function of the file admin/deactivateteach.php. The manipulation of the argument selector leads to sql injection. It is possible t... Read more
Affected Products : online_courseware- Published: Apr. 07, 2024
- Modified: Jan. 17, 2025
-
9.8
CRITICALCVE-2024-36684
In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.... Read more
Affected Products : pk_customlinks- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6744
The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remo... Read more
Affected Products : secure_email_gateway- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31032
An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component.... Read more
Affected Products :- Published: Mar. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9294
RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without authentication via RMI ports.... Read more
Affected Products : device_manager- EPSS Score: %4.44
- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-6951
A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book Store System 1.0. This affects an unknown part of the file admin_delete.php. The manipulation of the argument bookisbn leads to sql injection. It is possible... Read more
- Published: Jul. 21, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28610
The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system.... Read more
- EPSS Score: %0.27
- Published: Mar. 23, 2023
- Modified: Feb. 26, 2025
-
9.8
CRITICALCVE-2024-7081
A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file expcatadd.php. The manipulation of the argument id/title leads to sql injection. The... Read more
- Published: Jul. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-27922
TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure handling of HTTP requests by the @tomphttp/bare-server-node package. This flaw potentially exposes the users of the package to manipulatio... Read more
Affected Products :- Published: Mar. 21, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-7281
A vulnerability classified as critical has been found in SourceCodester Lot Reservation Management System 1.0. Affected is an unknown function of the file /admin/index.php?page=manage_lot. The manipulation of the argument id leads to sql injection. It is ... Read more
Affected Products : lot_reservation_management_system- Published: Jul. 31, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2024-7441
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-b... Read more
- Published: Aug. 03, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7461
A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of the file /authMonitCallcenter of the component monitcallcenter. The manipulation of the argument u... Read more
Affected Products : administracao_pabx- Published: Aug. 05, 2024
- Modified: Sep. 11, 2024
-
9.8
CRITICALCVE-2024-7500
A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of the file admin/admin_class.php. The manipulation of the argument img leads to unrestricted upl... Read more
Affected Products : airline_reservation_system- Published: Aug. 06, 2024
- Modified: Sep. 11, 2024
-
9.8
CRITICALCVE-2022-23366
HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.... Read more
Affected Products : hms- EPSS Score: %0.23
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28731
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Jooml... Read more
Affected Products : acymailing- EPSS Score: %2.07
- Published: Mar. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23399
A stack-based buffer overflow vulnerability exists in the confsrv set_port_fwd_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packe... Read more
- EPSS Score: %0.44
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-7742
A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical. Affected is the function multiDownload of the file /api/file/multiDownload of the component API Endpoint. The manipulation of the argument file leads to server-side ... Read more
Affected Products : ltcms- Published: Aug. 13, 2024
- Modified: Aug. 21, 2024