Latest CVE Feed
-
9.8
CRITICALCVE-2023-24734
An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file.... Read more
Affected Products : pmb- EPSS Score: %9.85
- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25569
Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.... Read more
Affected Products : sgsetup- EPSS Score: %1.80
- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28322
SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.... Read more
Affected Products : event_management- Published: Apr. 26, 2024
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2024-28557
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.... Read more
Affected Products : php_task_management_system- Published: Apr. 15, 2024
- Modified: Mar. 31, 2025
-
9.8
CRITICALCVE-2024-3423
A vulnerability was found in SourceCodester Online Courseware 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/activateteach.php. The manipulation of the argument selector leads to sql injection. The attack ... Read more
Affected Products : online_courseware- Published: Apr. 07, 2024
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2024-23679
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes. ... Read more
Affected Products : xp- EPSS Score: %0.90
- Published: Jan. 19, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-4671
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software ECOP allows Command Line Execution through SQL Injection.This issue affects ECOP: before 32255.... Read more
Affected Products : ecop- EPSS Score: %0.09
- Published: Dec. 28, 2023
- Modified: Nov. 25, 2024
-
9.8
CRITICALCVE-2023-4673
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sanalogy Turasistan allows SQL Injection.This issue affects Turasistan: before 20230911 . ... Read more
Affected Products : turasistan- EPSS Score: %0.14
- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41555
Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.... Read more
- EPSS Score: %0.12
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32744
Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gain access to files which are currently opened by other users in the Collabora Online editor. For successful... Read more
- EPSS Score: %0.75
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46817
An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attacke... Read more
Affected Products : phpfox- EPSS Score: %0.77
- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25729
Memory corruption in modem due to improper length check while copying into memory... Read more
Affected Products : wcd9380_firmware wcd9385_firmware wcn3980_firmware wcn3998_firmware wcn6855_firmware wcn6856_firmware wcn7850_firmware wcn7851_firmware wsa8810_firmware wsa8815_firmware +50 more products- EPSS Score: %0.14
- Published: Feb. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23636
SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protect... Read more
Affected Products : sofarpc- EPSS Score: %0.55
- Published: Jan. 23, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25767
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.... Read more
Affected Products : ureport2- EPSS Score: %3.10
- Published: May. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32824
Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet... Read more
Affected Products : dubbo- EPSS Score: %13.06
- Published: Jan. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.53
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3254
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, lea... Read more
- EPSS Score: %18.49
- Published: Oct. 31, 2022
- Modified: May. 06, 2025
-
9.8
CRITICALCVE-2024-54363
Incorrect Privilege Assignment vulnerability in nssTheme Wp NssUser Register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through 1.0.0.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.8
CRITICALCVE-2024-25531
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtility/SearchCondiction.aspx.... Read more
Affected Products : ruvaroa- Published: May. 08, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2022-33211
memory corruption in modem due to improper check while calculating size of serialized CoAP message... Read more
Affected Products : mdm9206_firmware wcd9330_firmware mdm9205_firmware qca4004_firmware wcd9306_firmware mdm8207_firmware mdm9207_firmware qts110_firmware snapdragon_wear_1300_firmware snapdragon_wear_1100_firmware +20 more products- EPSS Score: %0.12
- Published: Apr. 13, 2023
- Modified: Nov. 21, 2024