Latest CVE Feed
-
9.8
CRITICALCVE-2020-24030
ForLogic Qualiex v1 and v3 has weak token expiration. This allows remote unauthenticated privilege escalation and access to sensitive data via token reuse.... Read more
Affected Products : qualiex- EPSS Score: %1.42
- Published: Sep. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25079
TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.... Read more
- EPSS Score: %5.66
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25132
A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.... Read more
- EPSS Score: %4.46
- Published: Feb. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3680
A vulnerability classified as critical has been found in SourceCodester Lost and Found Information System 1.0. This affects an unknown part of the file /classes/Master.php?f=save_item of the component HTTP POST Request Handler. The manipulation of the arg... Read more
Affected Products : lost_and_found_information_system- EPSS Score: %0.04
- Published: Jul. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0989
A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the function del_sn_db of the file /application/index/controller/Service.php. The manipulation of the argument f... Read more
Affected Products : kuerp- EPSS Score: %0.11
- Published: Jan. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10021
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /php/manage_purchase.php?action=search&tag=VOUCHER_NUMBER. The manipulation of the a... Read more
Affected Products : pharmacy_management_system- Published: Oct. 16, 2024
- Modified: Oct. 21, 2024
-
9.8
CRITICALCVE-2023-3682
A vulnerability, which was classified as critical, was found in Nesote Inout Blockchain EasyPayments 1.0. Affected is an unknown function of the file /index.php/payment/getcoinaddress of the component POST Parameter Handler. The manipulation of the argume... Read more
Affected Products : inout_blockchain_easypayments- EPSS Score: %0.05
- Published: Jul. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43389
A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable de... Read more
- EPSS Score: %0.86
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10140
A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. Affected by this issue is some unknown functionality of the file /manage_supplier.php. The manipulation of the argument id leads to sql inje... Read more
Affected Products : pharmacy_management_system- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2025-26003
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.... Read more
- Published: Mar. 26, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2019-10542
Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sn... Read more
Affected Products : qca6574au_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware mdm9150_firmware qca6174a_firmware qca9377_firmware mdm9650_firmware +48 more products- EPSS Score: %0.34
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-2677
A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /changeidproof.php. The manipulation of the argument editid leads to sql injection. The attack c... Read more
- Published: Mar. 24, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-37144
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.... Read more
- EPSS Score: %1.14
- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-27671
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Device Impersonation OVE-20230524-0015.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 01, 2025
-
9.8
CRITICALCVE-2025-28238
Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10/4ASI allows attackers to execute a session hijacking attack.... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-26390
A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to... Read more
- Published: May. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-33752
CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.... Read more
Affected Products : ca_automic_automation- EPSS Score: %1.71
- Published: Jun. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25347
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.... Read more
Affected Products : diaenergie- EPSS Score: %0.80
- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29474
inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23552.... Read more
- EPSS Score: %0.54
- Published: Apr. 06, 2023
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2025-29385
In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.... Read more
- Published: Mar. 14, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Memory Corruption