Latest CVE Feed
-
9.8
CRITICALCVE-2024-52433
Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free allows Object Injection.This issue affects My Geo Posts Free: from n/a through 1.2.... Read more
Affected Products : my_geo_posts_free- Published: Nov. 18, 2024
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2022-24571
Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.... Read more
Affected Products : car_driving_school_management_system- EPSS Score: %0.48
- Published: Feb. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4006
Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.11
- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000800
zephyr-rtos version 1.12.0 contains a NULL base pointer reference vulnerability in sys_ring_buf_put(), sys_ring_buf_get() that can result in CPU Page Fault (error code 0x00000010). This attack appear to be exploitable via a malicious application call the ... Read more
- EPSS Score: %0.37
- Published: Sep. 06, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24652
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.... Read more
Affected Products : sentcms- EPSS Score: %2.65
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000824
MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.... Read more
Affected Products : megamek- EPSS Score: %1.98
- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5335
The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store... Read more
Affected Products : ultimate_store_kit- Published: Aug. 21, 2024
- Modified: Jul. 10, 2025
-
9.8
CRITICALCVE-2023-49716
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer. ... Read more
- EPSS Score: %0.08
- Published: Feb. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-49318
Deserialization of Untrusted Data vulnerability in Scott Olson My Reading Library allows Object Injection.This issue affects My Reading Library: from n/a through 1.0.... Read more
Affected Products :- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
9.8
CRITICALCVE-2022-29351
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.... Read more
Affected Products : tiddlywiki5- EPSS Score: %1.28
- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45334
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the characters received and they are sent unfiltered to the database... Read more
- EPSS Score: %0.10
- Published: Nov. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45498
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.... Read more
Affected Products : vinchin_backup_and_recovery- EPSS Score: %79.46
- Published: Oct. 27, 2023
- Modified: Jun. 12, 2025
-
9.8
CRITICALCVE-2024-52765
H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.... Read more
- Published: Nov. 20, 2024
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2023-45484
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiGuestBasic.... Read more
- EPSS Score: %0.26
- Published: Nov. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5882
While parsing a Flac file with a corrupted comment block, a buffer over-read can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear.... Read more
Affected Products : msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware mdm9650_firmware msm8909w_firmware sdx20_firmware mdm9206_firmware +38 more products- EPSS Score: %0.37
- Published: Jul. 06, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22212
Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended... Read more
- EPSS Score: %1.15
- Published: Jan. 18, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40545
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests. ... Read more
Affected Products : pingfederate- EPSS Score: %0.07
- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-31531
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).... Read more
Affected Products : manageengine_servicedesk_plus_msp- EPSS Score: %5.64
- Published: Jun. 29, 2021
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2021-40417
When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate th... Read more
Affected Products : davinci_resolve- EPSS Score: %1.54
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1379
A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file addmem.php of the component POST Parameter Handler. The manipulation o... Read more
Affected Products : friendly_island_pizza_website_and_ordering_system- EPSS Score: %0.16
- Published: Mar. 15, 2023
- Modified: Nov. 21, 2024