Latest CVE Feed
-
9.8
CRITICALCVE-2024-42336
Servision - CWE-287: Improper Authentication... Read more
Affected Products : ivg_webmax- Published: Aug. 20, 2024
- Modified: Aug. 27, 2024
-
9.8
CRITICALCVE-2023-4181
A vulnerability, which was classified as critical, has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this issue is some unknown functionality of the file /vm/admin/delete-doctor.php?id=2 of the component... Read more
- EPSS Score: %0.06
- Published: Aug. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37266
CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improvin... Read more
Affected Products : casaos- EPSS Score: %87.97
- Published: Jul. 17, 2023
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2024-42520
TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42558
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_modify_room.php.... Read more
Affected Products : hotel_management_system- Published: Aug. 20, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2024-42572
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.... Read more
Affected Products : school_management_system- Published: Aug. 20, 2024
- Modified: Aug. 21, 2024
-
9.8
CRITICALCVE-2024-42637
H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.... Read more
- Published: Aug. 16, 2024
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2024-42757
Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.... Read more
Affected Products :- Published: Aug. 15, 2024
- Modified: Aug. 20, 2024
-
9.8
CRITICALCVE-2022-23364
HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php.... Read more
Affected Products : hms- EPSS Score: %0.26
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9874
Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 and Sitecore XP 7.5 to 8.2 allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP P... Read more
- Actively Exploited
- EPSS Score: %25.05
- Published: May. 31, 2019
- Modified: Apr. 04, 2025
-
9.8
CRITICALCVE-2024-46340
TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.... Read more
- Published: Dec. 10, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-29243
Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the vpn_client_ip parameter at /apply.cgi.... Read more
- Published: Mar. 21, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-28001
Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter.... Read more
Affected Products : movie_seat_reservation- EPSS Score: %0.45
- Published: Apr. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37172
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.... Read more
- EPSS Score: %1.45
- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9950
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability. The... Read more
- EPSS Score: %0.80
- Published: Apr. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4345
The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process' function in the 'startklarDropZoneUploadProcess' class in versions up to, and including, 1.7.13. This mak... Read more
Affected Products : startklar_elmentor_addons- Published: May. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1698
The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient esca... Read more
Affected Products : notificationx- Published: Feb. 27, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28093
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : online_sports_complex_booking_system- EPSS Score: %0.94
- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-43698
Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin rights on the system.... Read more
Affected Products :- Published: Oct. 22, 2024
- Modified: Oct. 23, 2024
-
9.8
CRITICALCVE-2023-37700
Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.... Read more
- EPSS Score: %0.12
- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024