Latest CVE Feed
-
9.8
CRITICALCVE-2018-8914
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.... Read more
Affected Products : media_server- EPSS Score: %0.34
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-4150
IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 17... Read more
Affected Products : security_siteprotector_system- EPSS Score: %0.06
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8943
There is a SQL injection in the PHPSHE 1.6 userbank parameter.... Read more
Affected Products : phpshe- EPSS Score: %0.26
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-15806
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.html. Any user c... Read more
- EPSS Score: %0.24
- Published: Aug. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43893
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.... Read more
- EPSS Score: %2.35
- Published: Oct. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43902
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.... Read more
Affected Products : emsigner- EPSS Score: %0.32
- Published: Nov. 14, 2023
- Modified: Jan. 08, 2025
-
9.8
CRITICALCVE-2023-0883
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-opos/index.php. The manipulation of the argument ID leads to sql injection. The attack c... Read more
- EPSS Score: %0.05
- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-4207
IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP requ... Read more
- EPSS Score: %1.98
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43981
Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.... Read more
Affected Products : test_site_creator- EPSS Score: %0.10
- Published: Oct. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16920
v5/config/system.php in dayrui FineCms 5.2.0 has a default SYS_KEY value and does not require key regeneration for each installation, which allows remote attackers to upload arbitrary .php files via a member api swfupload action to index.php.... Read more
- EPSS Score: %0.71
- Published: Nov. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-12002
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.... Read more
Affected Products : webaccess- EPSS Score: %31.45
- Published: May. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-9031
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.... Read more
Affected Products : sentry_vision- EPSS Score: %0.78
- Published: Mar. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-45186
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.... Read more
Affected Products :- Published: Oct. 02, 2024
- Modified: Oct. 04, 2024
-
9.8
CRITICALCVE-2023-0946
A vulnerability has been found in SourceCodester Best POS Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file billing/index.php?id=9. The manipulation of the argument id leads to sql inj... Read more
- EPSS Score: %0.04
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44080
An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component.... Read more
Affected Products : codefever- EPSS Score: %4.02
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4410
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The expl... Read more
- EPSS Score: %1.11
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36219
An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An attacker can chain multiple enclave calls to prepare a stack that contains a v... Read more
Affected Products : sgxwallet- EPSS Score: %0.31
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4407
A vulnerability classified as critical was found in Codecanyon Credit Lite 1.5.4. Affected by this vulnerability is an unknown functionality of the file /portal/reports/account_statement of the component POST Request Handler. The manipulation of the argum... Read more
Affected Products : credit_lite- EPSS Score: %0.06
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0635
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104... Read more
- EPSS Score: %0.12
- Published: Jun. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12481
The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonstrated by reading the "User password" field with the Drozer post.capture.clipboard module.... Read more
Affected Products : the_olive_tree_ftp_server- EPSS Score: %0.34
- Published: Jun. 15, 2018
- Modified: Nov. 21, 2024