Latest CVE Feed
-
9.8
CRITICALCVE-2019-3947
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database server.... Read more
Affected Products : v-server- EPSS Score: %0.42
- Published: Jun. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24734
An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file.... Read more
Affected Products : pmb- EPSS Score: %9.85
- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25569
Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.... Read more
Affected Products : sgsetup- EPSS Score: %1.80
- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28322
SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.... Read more
Affected Products : event_management- Published: Apr. 26, 2024
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2024-28557
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.... Read more
Affected Products : php_task_management_system- Published: Apr. 15, 2024
- Modified: Mar. 31, 2025
-
9.8
CRITICALCVE-2024-3423
A vulnerability was found in SourceCodester Online Courseware 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/activateteach.php. The manipulation of the argument selector leads to sql injection. The attack ... Read more
Affected Products : online_courseware- Published: Apr. 07, 2024
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2024-23679
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes. ... Read more
Affected Products : xp- EPSS Score: %0.90
- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-4671
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software ECOP allows Command Line Execution through SQL Injection.This issue affects ECOP: before 32255.... Read more
Affected Products : ecop- EPSS Score: %0.09
- Published: Dec. 28, 2023
- Modified: Nov. 25, 2024
-
9.8
CRITICALCVE-2023-4673
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sanalogy Turasistan allows SQL Injection.This issue affects Turasistan: before 20230911 . ... Read more
Affected Products : turasistan- EPSS Score: %0.14
- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41555
Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.... Read more
- EPSS Score: %0.12
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32744
Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gain access to files which are currently opened by other users in the Collabora Online editor. For successful... Read more
- EPSS Score: %0.75
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46817
An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attacke... Read more
Affected Products : phpfox- EPSS Score: %0.77
- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25729
Memory corruption in modem due to improper length check while copying into memory... Read more
Affected Products : wcd9380_firmware wcd9385_firmware wcn3980_firmware wcn3998_firmware wcn6855_firmware wcn6856_firmware wcn7850_firmware wcn7851_firmware wsa8810_firmware wsa8815_firmware +50 more products- EPSS Score: %0.14
- Published: Feb. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23636
SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protect... Read more
Affected Products : sofarpc- EPSS Score: %0.55
- Published: Jan. 23, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25767
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.... Read more
Affected Products : ureport2- EPSS Score: %3.10
- Published: May. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32824
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet... Read more
Affected Products : dubbo- EPSS Score: %13.06
- Published: Jan. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.53
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3254
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, lea... Read more
- EPSS Score: %18.49
- Published: Oct. 31, 2022
- Modified: May. 06, 2025
-
9.8
CRITICALCVE-2024-54363
Incorrect Privilege Assignment vulnerability in nssTheme Wp NssUser Register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through 1.0.0.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.8
CRITICALCVE-2024-25531
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx.... Read more
Affected Products : ruvaroa- Published: May. 08, 2024
- Modified: Apr. 17, 2025