Latest CVE Feed
-
9.8
CRITICALCVE-2020-12002
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.... Read more
Affected Products : webaccess- EPSS Score: %31.45
- Published: May. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-9031
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.... Read more
Affected Products : sentry_vision- EPSS Score: %0.78
- Published: Mar. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-45186
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2023-0946
A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file billing/index.php?id=9. The manipulation of the argument id leads to sql inj... Read more
- EPSS Score: %0.04
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44080
An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component.... Read more
Affected Products : codefever- EPSS Score: %4.02
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4410
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The expl... Read more
- EPSS Score: %1.11
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36219
An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An attacker can chain multiple enclave calls to prepare a stack that contains a v... Read more
Affected Products : sgxwallet- EPSS Score: %0.31
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4407
A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4. Affected by this vulnerability is an unknown functionality of the file /portal/reports/account_statement of the component POST Request Handler. The manipulation of the argum... Read more
Affected Products : credit_lite- EPSS Score: %0.06
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0635
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104... Read more
- EPSS Score: %0.12
- Published: Jun. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12481
The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonstrated by reading the "User password" field with the Drozer post.capture.clipboard module.... Read more
Affected Products : the_olive_tree_ftp_server- EPSS Score: %0.34
- Published: Jun. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5960
Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.... Read more
Affected Products : panel- Published: Sep. 18, 2024
- Modified: Nov. 27, 2024
-
9.8
CRITICALCVE-2023-44169
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.... Read more
Affected Products : seacms- EPSS Score: %0.36
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28412
Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package.... Read more
Affected Products : car_driving_school_management_system- EPSS Score: %0.24
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12548
In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native code.... Read more
Affected Products : openj9- EPSS Score: %0.42
- Published: Jan. 31, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-9162
Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.... Read more
- EPSS Score: %5.12
- Published: Mar. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28437
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=Admin&userid=3.... Read more
Affected Products : baby_care_system- EPSS Score: %0.25
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13850
The "Firebase Cloud Messaging (FCM) + Advance Admin Panel" component supporting Firebase Push Notification on iOS (through 2017-10-26) allows SQL injection via the /advance_push/public/login username parameter.... Read more
Affected Products : firebase_push_notification_on_ios_\/_fcm_\+_advance_admin_panel- EPSS Score: %0.26
- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28452
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.... Read more
Affected Products : laundry_management_system- EPSS Score: %11.78
- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1260
A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIndex of the file /api/controllers/admin/app/ComboController.php of the component API. The manipulation of the argument pic_url leads to ... Read more
Affected Products : jpshop- EPSS Score: %0.08
- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16924
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collection... Read more
Affected Products : manageengine_desktop_central- EPSS Score: %1.82
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024