Latest CVE Feed
-
9.8
CRITICALCVE-2020-0217
In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: A... Read more
Affected Products : android- EPSS Score: %0.76
- Published: Jun. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-46640
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL... Read more
Affected Products : seacms- Published: Sep. 20, 2024
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2022-48120
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.... Read more
Affected Products : hospital_management_system- EPSS Score: %0.09
- Published: Jan. 20, 2023
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2023-38865
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.... Read more
- EPSS Score: %1.14
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0230
There is a possible out of bounds write due to an incorrect bounds check. Product: AndroidVersions: Android SoCAndroid ID: A-156337262... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39010
BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.... Read more
Affected Products : boofcv- EPSS Score: %0.12
- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39016
bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.... Read more
- EPSS Score: %0.10
- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43792
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.... Read more
Affected Products : basercms- EPSS Score: %0.34
- Published: Oct. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39150
ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387.... Read more
Affected Products : conemu- EPSS Score: %0.20
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24171
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and ... Read more
- EPSS Score: %15.55
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28812
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.... Read more
- EPSS Score: %0.49
- Published: Sep. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44166
The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : online_movie_ticket_booking_system- EPSS Score: %0.22
- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26064
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.... Read more
Affected Products : cxtpc_firmware cstpc_firmware mxtct_firmware mxtpm_firmware cxtmm_firmware mslsg_firmware mxlsg_firmware mslbd_firmware mxlbd_firmware msngm_firmware +207 more products- EPSS Score: %0.32
- Published: Apr. 10, 2023
- Modified: Feb. 11, 2025
-
9.8
CRITICALCVE-2024-5085
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function. This makes it possible for unauthentica... Read more
Affected Products : hash_form- Published: May. 23, 2024
- Modified: Mar. 01, 2025
-
9.8
CRITICALCVE-2023-4411
A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The ex... Read more
- EPSS Score: %1.11
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39021
wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument.... Read more
Affected Products : wix_embedded_mysql- EPSS Score: %0.11
- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-51260
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.... Read more
- Published: Oct. 31, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2014-8563
Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.... Read more
Affected Products : zimbra_collaboration_server- EPSS Score: %5.17
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-38773
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Blind SQL Injection.This issue affects FormLift for Infusionsoft Web Forms: from n/a through 7.5.... Read more
Affected Products : formlift_for_infusionsoft_web_forms- Published: Jul. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24431
All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization.... Read more
Affected Products : abacus-ext-cmdline- EPSS Score: %0.32
- Published: Dec. 21, 2022
- Modified: Apr. 15, 2025