Latest CVE Feed
-
9.8
CRITICALCVE-2023-46557
TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAPVLAN.... Read more
- EPSS Score: %0.21
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5360
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.... Read more
Affected Products : royal_elementor_addons- EPSS Score: %93.14
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0638
A vulnerability has been found in TRENDnet TEW-811DRU 1.0.10.0 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack can be initiated remotely. The explo... Read more
- EPSS Score: %0.22
- Published: Feb. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-43923
Missing Authorization vulnerability in Arraytics Timetics allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Timetics: from n/a through 1.0.23.... Read more
Affected Products : wp_timetics- Published: Nov. 01, 2024
- Modified: Nov. 13, 2024
-
9.8
CRITICALCVE-2024-25825
FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the root password saved as a wildcard. This allows attackers to gain root access without a password.... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 11, 2024
-
9.8
CRITICALCVE-2023-48687
Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'from' parameter of the reservation.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : railway_reservation_system- EPSS Score: %0.15
- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-28503
The package copy-props before 2.0.5 are vulnerable to Prototype Pollution via the main functionality.... Read more
Affected Products : copy-props- EPSS Score: %0.58
- Published: Mar. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48720
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : student_result_management_system- EPSS Score: %0.15
- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4873
A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230906. Affected is an unknown function of the file /importexport.php. The manipulation of the argument ... Read more
- EPSS Score: %7.02
- Published: Sep. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31956
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incident_reports/manage_report.php?id=.... Read more
Affected Products : rescue_dispatch_management_system- EPSS Score: %0.25
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10845
A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. The manipulation of the argument id leads to sql injection. The attack can be ... Read more
- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2023-52333
Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product... Read more
Affected Products : allegra- Published: Nov. 22, 2024
- Modified: Jan. 03, 2025
-
9.8
CRITICALCVE-2023-0707
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been rated as critical. Affected by this issue is the function delete_record of the file function.php. The manipulation of the argument id leads to sql injection. VD... Read more
Affected Products : medical_certificate_generator_app- EPSS Score: %0.04
- Published: Feb. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-35689
A potential vulnerability in the Oracle Talent Acquisition Cloud - Taleo Enterprise Edition. This high severity potential vulnerability allows attackers to perform remote code execution on Taleo Enterprise Edition system. Successful attacks of this vulner... Read more
Affected Products : talent_acquisition_cloud- EPSS Score: %2.52
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5034
A vulnerability classified as problematic was found in SourceCodester My Food Recipe 1.0. This vulnerability affects unknown code of the file index.php of the component Image Upload Handler. The manipulation leads to unrestricted upload. The attack can be... Read more
- EPSS Score: %0.07
- Published: Sep. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36588
In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.... Read more
- EPSS Score: %0.27
- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-50372
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1... Read more
Affected Products :- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
9.8
CRITICALCVE-2022-42064
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.... Read more
Affected Products : online_diagnostic_lab_management_system- EPSS Score: %0.02
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2022-28115
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.... Read more
Affected Products : online_sports_complex_booking- EPSS Score: %0.29
- Published: Apr. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8914
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.... Read more
Affected Products : media_server- EPSS Score: %0.34
- Published: May. 10, 2018
- Modified: Nov. 21, 2024