Latest CVE Feed
-
9.8
CRITICALCVE-2018-9162
Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.... Read more
- EPSS Score: %5.12
- Published: Mar. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28437
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=Admin&userid=3.... Read more
Affected Products : baby_care_system- EPSS Score: %0.25
- Published: Apr. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13850
The "Firebase Cloud Messaging (FCM) + Advance Admin Panel" component supporting Firebase Push Notification on iOS (through 2017-10-26) allows SQL injection via the /advance_push/public/login username parameter.... Read more
Affected Products : firebase_push_notification_on_ios_\/_fcm_\+_advance_admin_panel- EPSS Score: %0.26
- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28452
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.... Read more
Affected Products : laundry_management_system- EPSS Score: %11.78
- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1260
A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIndex of the file /api/controllers/admin/app/ComboController.php of the component API. The manipulation of the argument pic_url leads to ... Read more
Affected Products : jpshop- EPSS Score: %0.08
- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16924
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collection... Read more
Affected Products : manageengine_desktop_central- EPSS Score: %1.82
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-2147
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.... Read more
Affected Products : phpbugtracker- EPSS Score: %0.37
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-10374
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.... Read more
Affected Products : prtg_network_monitor- EPSS Score: %4.89
- Published: Mar. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28533
Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.... Read more
Affected Products : medical_hub_directory_site- EPSS Score: %0.24
- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3645
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')... Read more
Affected Products : merge- EPSS Score: %0.45
- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1784
A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit h... Read more
Affected Products : jeecg_boot- EPSS Score: %0.10
- Published: Mar. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1040
A vulnerability, which was classified as critical, has been found in SourceCodester Online Graduate Tracer System 1.0. Affected by this issue is some unknown functionality of the file tracking/admin/add_acc.php. The manipulation of the argument id leads t... Read more
Affected Products : online_graduate_tracer_system online_graduate_tracer_system online_graduate_tracer_system- EPSS Score: %0.05
- Published: Feb. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36624
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.... Read more
Affected Products : phone_shop_sales_management_system- EPSS Score: %0.15
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-27113
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by ex... Read more
Affected Products : soplanning- Published: Sep. 11, 2024
- Modified: Sep. 18, 2024
-
9.8
CRITICALCVE-2018-12671
An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including all password sets set within the camera. This information c... Read more
Affected Products : h.264_poe_ip_camera_firmware sv-b01poe-1080p-l sv-b11vpoe-1080p-l sv-d02poe-1080p-l- EPSS Score: %0.35
- Published: Oct. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-0397
In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: Android... Read more
Affected Products : android- EPSS Score: %13.56
- Published: Mar. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1251
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03.... Read more
Affected Products : wolvox- EPSS Score: %0.07
- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41300
ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can access the page and obtain privilege with full functionality.... Read more
- EPSS Score: %0.42
- Published: Sep. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1792
A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/fields/manage_field.php of the component GET Parameter Handler. The manipu... Read more
Affected Products : simple_mobile_comparison_website- EPSS Score: %0.06
- Published: Apr. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-4307
A vulnerability was found in Yomguithereal Baobab up to 2.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prot... Read more
Affected Products : baobab- EPSS Score: %0.16
- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024