Latest CVE Feed
-
9.8
CRITICALCVE-2022-36705
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php.... Read more
Affected Products : ingredients_stock_management_system- EPSS Score: %0.11
- Published: Aug. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46262
Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.... Read more
- EPSS Score: %1.00
- Published: Feb. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24138
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.... Read more
- EPSS Score: %1.45
- Published: Feb. 03, 2023
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2022-37071
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateOne2One.... Read more
- EPSS Score: %0.44
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37072
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanLinkspyMulti.... Read more
- EPSS Score: %0.44
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3241
The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more
Affected Products : build_app_online- EPSS Score: %0.64
- Published: Jan. 02, 2023
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2022-37095
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateWanParams.... Read more
- EPSS Score: %0.44
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37091
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditWlanMacList.... Read more
- EPSS Score: %0.44
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37100
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function UpdateMacClone.... Read more
- EPSS Score: %0.44
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10759
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.... Read more
Affected Products : projectpier- EPSS Score: %1.22
- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33561
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.... Read more
Affected Products : time_slots_booking_calendar- EPSS Score: %0.11
- Published: Aug. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11805
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.... Read more
- EPSS Score: %0.44
- Published: Sep. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37089
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditMacList.... Read more
- EPSS Score: %0.44
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37471
Open Access Management (OpenAM) is an access management solution that includes Authentication, SSO, Authorization, Federation, Entitlements and Web Services Security. OpenAM up to version 14.7.2 does not properly validate the signature of SAML responses r... Read more
Affected Products : openam- EPSS Score: %1.01
- Published: Jul. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39675
SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.... Read more
Affected Products : simpleimportproduct- EPSS Score: %0.21
- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41554
Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter wpapsk_crypto at url /goform/WifiExtraSet.... Read more
- EPSS Score: %0.12
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38928
Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.... Read more
- EPSS Score: %1.64
- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32520
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32518. Affected Products: Data Center Ex... Read more
Affected Products : data_center_expert- EPSS Score: %0.16
- Published: Jan. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46557
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAPVLAN.... Read more
- EPSS Score: %0.21
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5360
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.... Read more
Affected Products : royal_elementor_addons- EPSS Score: %93.14
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024