Latest CVE Feed
-
9.8
CRITICALCVE-2022-27177
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2... Read more
Affected Products : consoleme- EPSS Score: %2.14
- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10614
Out of boundary access is possible as there is no validation of data accessed against the received size of the packet in case of malicious firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivi... Read more
Affected Products : sa6155p_firmware sdx55_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware qcs605_firmware sdx24_firmware +80 more products- EPSS Score: %0.29
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-12940
A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/student_action.php. The manipulation of the argument student_id leads to sql i... Read more
Affected Products : attendance_tracking_management_system- Published: Dec. 26, 2024
- Modified: Dec. 26, 2024
-
9.8
CRITICALCVE-2024-12981
A vulnerability was found in CodeAstro Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /bookingconfirm.php. The manipulation of the argument driver_id_from_dropdown leads to s... Read more
Affected Products : car_rental_system- Published: Dec. 27, 2024
- Modified: Mar. 05, 2025
-
9.8
CRITICALCVE-2023-48654
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset function... Read more
Affected Products : password_manager- EPSS Score: %0.16
- Published: Dec. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-13003
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /update_ed.php. The manipulation of the argument e_id leads to sql injection. T... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 29, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2022-2723
A vulnerability was found in SourceCodester Employee Management System. It has been classified as critical. Affected is an unknown function of the file /process/eprocess.php. The manipulation of the argument mailuid/pwd leads to sql injection. It is possi... Read more
Affected Products : employee_management_system employee_management_system employee_management_system- EPSS Score: %0.31
- Published: Aug. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-13035
A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/update_user.php. The manipulation of the argument id leads to sql injection. The attack can be initiated... Read more
- Published: Dec. 30, 2024
- Modified: Jan. 06, 2025
-
9.8
CRITICALCVE-2018-0645
MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors.... Read more
Affected Products : mtappjquery- EPSS Score: %1.27
- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23624
A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root. ... Read more
- EPSS Score: %10.01
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-26339
A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability in multip... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2020-27678
An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.... Read more
- EPSS Score: %0.46
- Published: Oct. 26, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27263
An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary code via a crafted file.... Read more
Affected Products : strapi- EPSS Score: %2.18
- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48685
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'psd' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : railway_reservation_system- EPSS Score: %0.15
- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-28100
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.... Read more
Affected Products : dingfanzu- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-26210
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerabilit... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware a3100r a3000ru a830r a800r +2 more products- EPSS Score: %10.18
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-41368
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php... Read more
Affected Products : phoniebox- Published: Aug. 29, 2024
- Modified: Sep. 04, 2024
-
9.8
CRITICALCVE-2024-41444
SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.... Read more
Affected Products : seacms- Published: Aug. 26, 2024
- Modified: Sep. 05, 2024
-
9.8
CRITICALCVE-2024-41468
Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand... Read more
- Published: Jul. 25, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-36487
The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.... Read more
Affected Products : ilias- EPSS Score: %0.44
- Published: Jun. 29, 2023
- Modified: Nov. 26, 2024