Latest CVE Feed
-
9.8
CRITICALCVE-2024-43091
In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.... Read more
Affected Products : android- Published: Nov. 13, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2022-44751
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is di... Read more
Affected Products : notes- EPSS Score: %2.38
- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-11967
A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/reset-password.php. The manipulation of the argument email leads to sql injection. It is possib... Read more
Affected Products : complaint_management_system- Published: Nov. 28, 2024
- Modified: Dec. 03, 2024
-
9.8
CRITICALCVE-2023-34399
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The version of boost library contains vulnerability integer overflow.... Read more
Affected Products : headunit_ntg6_mercedes-benz_user_experience- Published: Feb. 13, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2022-45712
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.... Read more
- EPSS Score: %0.12
- Published: Dec. 23, 2022
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2019-18572
The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication.... Read more
Affected Products : rsa_identity_governance_and_lifecycle- EPSS Score: %1.31
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27063
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted ... Read more
- EPSS Score: %0.50
- Published: Mar. 13, 2023
- Modified: Feb. 27, 2025
-
9.8
CRITICALCVE-2022-45010
Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php.... Read more
Affected Products : simple_phone_book\/directory_web_app- EPSS Score: %0.07
- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2024-39736
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, includin... Read more
- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45717
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET request.... Read more
- EPSS Score: %0.66
- Published: Dec. 23, 2022
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2024-12188
A vulnerability was found in 1000 Projects Library Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /brains/stu.php. The manipulation of the argument useri leads to sql injecti... Read more
Affected Products : library_management_system- Published: Dec. 05, 2024
- Modified: Dec. 10, 2024
-
9.8
CRITICALCVE-2014-7175
FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.... Read more
- EPSS Score: %0.43
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39453
A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.... Read more
Affected Products : imagegear- EPSS Score: %0.32
- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-12228
A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unknown function of the file /admin/user-search.php. The manipulation of the argument search leads to sql injection. It is possible to laun... Read more
Affected Products : complaint_management_system- Published: Dec. 05, 2024
- Modified: Dec. 10, 2024
-
9.8
CRITICALCVE-2023-34800
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.... Read more
- EPSS Score: %68.95
- Published: Jun. 15, 2023
- Modified: Dec. 16, 2024
-
9.8
CRITICALCVE-2024-40110
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php.... Read more
- Published: Jul. 12, 2024
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2024-40393
Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.... Read more
Affected Products : online_clinic_management_system- Published: Jul. 16, 2024
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2024-1228
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before vers... Read more
Affected Products : przychodnia- Published: Jun. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39375
TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.... Read more
- Published: Jun. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9010
An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGate... Read more
- EPSS Score: %0.47
- Published: Aug. 15, 2019
- Modified: Nov. 21, 2024