Latest CVE Feed
-
9.8
CRITICALCVE-2018-19328
LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal.... Read more
Affected Products : laobancms- EPSS Score: %0.57
- Published: Nov. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0683
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via Cookie data.... Read more
- EPSS Score: %6.74
- Published: Nov. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0485
A vulnerability, which was classified as critical, was found in code-projects Fighting Cock Information System 1.0. Affected is an unknown function of the file admin/pages/tables/add_con.php. The manipulation of the argument id leads to sql injection. It ... Read more
Affected Products : fighting_cock_information_system- EPSS Score: %0.05
- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0461
A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been classified as critical. Affected is an unknown function of the file deactivate.php of the component HTTP POST Request Handler. The manipulation of the argument haydi lead... Read more
- EPSS Score: %0.06
- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0471
A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin_route/dec_service_credits.php. The manipulation of the argument date leads to sql... Read more
- EPSS Score: %0.05
- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38689
A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following ver... Read more
- EPSS Score: %1.21
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38692
A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following ver... Read more
- EPSS Score: %1.21
- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31446
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.... Read more
- EPSS Score: %92.67
- Published: Jan. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2020-14096
Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.... Read more
- EPSS Score: %0.50
- Published: Sep. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-50090
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.... Read more
Affected Products : ureport2- EPSS Score: %0.10
- Published: Jan. 03, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-49665
Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
- EPSS Score: %0.07
- Published: Jan. 04, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49689
Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : job_portal- EPSS Score: %0.15
- Published: Dec. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34268
An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.... Read more
Affected Products : worldserver- EPSS Score: %0.16
- Published: Dec. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-0870
The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.... Read more
Affected Products : ffmpeg- EPSS Score: %0.46
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000194
October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.... Read more
Affected Products : october- EPSS Score: %0.41
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2025-5675
A vulnerability was found in Campcodes Online Teacher Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /trms/admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate lead... Read more
Affected Products : online_teacher_record_management_system- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
-
9.8
CRITICALCVE-2018-14564
An issue was discovered in libthulac.so in THULAC through 2018-02-25. A SEGV can occur in NGramFeature::find_bases in include/cb_ngram_feature.h.... Read more
Affected Products : thulac- EPSS Score: %0.43
- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14579
GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by inserting this code into the "Database Information" "Table prefix" form field, or obtain sensitive inform... Read more
Affected Products : golemcms- EPSS Score: %0.99
- Published: Jul. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-33434
An issue in tiagorlampert CHAOS before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` str... Read more
Affected Products :- Published: May. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3921
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE... Read more
Affected Products : listingo- EPSS Score: %28.90
- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025