Latest CVE Feed
-
9.8
CRITICALCVE-2023-39641
Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component PsaffiliateGetaffiliatesdetailsModuleFrontController::initContent().... Read more
Affected Products : full_affiliates- EPSS Score: %0.15
- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45173
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker c... Read more
Affected Products : vdesk- EPSS Score: %0.02
- Published: Apr. 14, 2023
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2023-39661
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.... Read more
Affected Products : pandasai- EPSS Score: %1.36
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39665
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the acStack_50 parameter.... Read more
- EPSS Score: %0.26
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45276
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.... Read more
Affected Products : yjcms- EPSS Score: %0.26
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2017-15976
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.... Read more
Affected Products : zeebuddy- EPSS Score: %2.51
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2022-22137
A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A specially-crafted malformed file can lead to an arbitrary free. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : imagegear- EPSS Score: %0.38
- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2216
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.... Read more
Affected Products : parse-url- EPSS Score: %0.20
- Published: Jun. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24752
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQ... Read more
- EPSS Score: %0.53
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33719
Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.... Read more
- EPSS Score: %0.16
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2679
A vulnerability was found in SourceCodester Interview Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /viewReport.php. The manipulation of the argument id with the input (UPDATEXML(9729,CONCAT(0... Read more
Affected Products : interview_management_system- EPSS Score: %0.23
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45551
An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.... Read more
- EPSS Score: %11.88
- Published: Mar. 03, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-30013
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.... Read more
- EPSS Score: %91.75
- Published: May. 05, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2024-1268
A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unknown part of the file update_product.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely... Read more
Affected Products : restaurant_pos_system- EPSS Score: %0.06
- Published: Feb. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30054
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.... Read more
- EPSS Score: %4.12
- Published: May. 05, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-43519
Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6430_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware +262 more products- EPSS Score: %0.11
- Published: Feb. 06, 2024
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2022-45699
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.... Read more
- EPSS Score: %90.15
- Published: Feb. 10, 2023
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-45709
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.... Read more
- EPSS Score: %0.66
- Published: Dec. 23, 2022
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2023-35813
Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.... Read more
- EPSS Score: %93.52
- Published: Jun. 17, 2023
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2023-35782
The ipandlanguageredirect extension before 5.1.2 for TYPO3 allows SQL Injection.... Read more
Affected Products : ipandlanguageredirect- EPSS Score: %0.29
- Published: Jun. 16, 2023
- Modified: Nov. 21, 2024