Latest CVE Feed
-
9.8
CRITICALCVE-2023-38632
async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in tcpsocket.hpp when processing malformed TCP packets.... Read more
Affected Products : asynchronous_sockets_for_c\+\+- EPSS Score: %26.78
- Published: Jul. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24010
A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerabil... Read more
- EPSS Score: %0.54
- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4620
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form... Read more
- Published: Jun. 07, 2024
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2020-0217
In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A... Read more
Affected Products : android- EPSS Score: %0.76
- Published: Jun. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-46640
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL... Read more
Affected Products : seacms- Published: Sep. 20, 2024
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2022-48120
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.... Read more
Affected Products : hospital_management_system- EPSS Score: %0.09
- Published: Jan. 20, 2023
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2023-38865
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.... Read more
- EPSS Score: %1.14
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0230
There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156337262... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39010
BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.... Read more
Affected Products : boofcv- EPSS Score: %0.12
- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39016
bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.... Read more
- EPSS Score: %0.10
- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43792
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.... Read more
Affected Products : basercms- EPSS Score: %0.34
- Published: Oct. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39150
ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387.... Read more
Affected Products : conemu- EPSS Score: %0.20
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24171
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and ... Read more
- EPSS Score: %15.55
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28812
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.... Read more
- EPSS Score: %0.49
- Published: Sep. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44166
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : online_movie_ticket_booking_system- EPSS Score: %0.22
- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26064
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.... Read more
Affected Products : cxtpc_firmware cstpc_firmware mxtct_firmware mxtpm_firmware cxtmm_firmware mslsg_firmware mxlsg_firmware mslbd_firmware mxlbd_firmware msngm_firmware +207 more products- EPSS Score: %0.32
- Published: Apr. 10, 2023
- Modified: Feb. 11, 2025
-
9.8
CRITICALCVE-2024-5085
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function. This makes it possible for unauthentica... Read more
Affected Products : hash_form- Published: May. 23, 2024
- Modified: Mar. 01, 2025
-
9.8
CRITICALCVE-2023-4411
A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The ex... Read more
- EPSS Score: %1.11
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39021
wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument.... Read more
Affected Products : wix_embedded_mysql- EPSS Score: %0.11
- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-51260
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.... Read more
- Published: Oct. 31, 2024
- Modified: Apr. 10, 2025