Latest CVE Feed
-
9.8
CRITICALCVE-2022-27263
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.... Read more
Affected Products : strapi- EPSS Score: %2.18
- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48685
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'psd' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : railway_reservation_system- EPSS Score: %0.15
- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-28100
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.... Read more
Affected Products : dingfanzu- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-26210
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerabilit... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware a3100r a3000ru a830r a800r +2 more products- EPSS Score: %10.18
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41368
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php... Read more
Affected Products : phoniebox- Published: Aug. 29, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-41444
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.... Read more
Affected Products : seacms- Published: Aug. 26, 2024
- Modified: Sep. 05, 2024
-
9.8
CRITICALCVE-2024-41468
Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand... Read more
- Published: Jul. 25, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-36487
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.... Read more
Affected Products : ilias- EPSS Score: %0.44
- Published: Jun. 29, 2023
- Modified: Nov. 26, 2024
-
9.8
CRITICALCVE-2024-45249
Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')... Read more
Affected Products : cavok- Published: Oct. 06, 2024
- Modified: May. 16, 2025
-
9.8
CRITICALCVE-2023-40784
DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.... Read more
Affected Products : dedecms- EPSS Score: %0.17
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-46323
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.... Read more
- EPSS Score: %0.10
- Published: Dec. 20, 2022
- Modified: Apr. 16, 2025
-
9.8
CRITICALCVE-2022-27466
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.... Read more
Affected Products : mcms- EPSS Score: %0.38
- Published: May. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40896
Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.... Read more
- EPSS Score: %0.12
- Published: Aug. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4092
SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to read sensitive data from the database, modify data (insert/update/delete), perform database administration operations a... Read more
Affected Products : arconte_aurea- EPSS Score: %0.14
- Published: Sep. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41618
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated ... Read more
Affected Products :- Published: Oct. 24, 2024
- Modified: Oct. 29, 2024
-
9.8
CRITICALCVE-2022-27479
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.... Read more
Affected Products : superset- EPSS Score: %4.32
- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41647
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-41645
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2020-26037
Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.... Read more
Affected Products : punkbuster- EPSS Score: %6.26
- Published: Aug. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4547
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the '~' character as the separator. An unauthenticated remote attacker can perf... Read more
Affected Products : diaenergie- Published: May. 06, 2024
- Modified: Jun. 27, 2025