Latest CVE Feed
-
9.8
CRITICALCVE-2024-33792
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.... Read more
- Published: May. 03, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-35156
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..... Read more
- EPSS Score: %0.08
- Published: Sep. 30, 2022
- Modified: May. 20, 2025
-
9.8
CRITICALCVE-2024-2571
A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage-admin.php. The manipulation leads to execution after redirect. The attack can be... Read more
- Published: Mar. 18, 2024
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2023-7017
Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an u... Read more
Affected Products :- Published: Mar. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38573
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a CombineFiles pathname is not validated.... Read more
- EPSS Score: %0.02
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49989
Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.... Read more
- Published: Mar. 07, 2024
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2019-10922
A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All versions), SIMATIC WinCC V7.2 and earlier (All versions), SIMATIC WinCC V7.3 and newer (All versions). An attacker with network access ... Read more
- EPSS Score: %1.49
- Published: May. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-1000075
Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function... Read more
Affected Products : gravity- EPSS Score: %0.85
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-1032
A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /application/index/controller/Databasesource.php of the component Test Connection Handler. The manipulation l... Read more
- EPSS Score: %0.08
- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15441
A vulnerability in the web framework code of Cisco Prime License Manager (PLM) could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries.... Read more
Affected Products : prime_license_manager- EPSS Score: %0.42
- Published: Nov. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17448
An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.... Read more
- EPSS Score: %0.61
- Published: Oct. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18389
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username wit... Read more
Affected Products : neo4j- EPSS Score: %0.76
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6220
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up to, and including, 1.0.26. This makes it possible for unauthenticated a... Read more
Affected Products : piotnet_forms- EPSS Score: %6.26
- Published: Jan. 11, 2024
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-49237
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.... Read more
- EPSS Score: %3.30
- Published: Jan. 09, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2021-38731
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.... Read more
Affected Products : semcms- EPSS Score: %0.34
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2019-16699
The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution.... Read more
Affected Products : sr_freecap- EPSS Score: %2.48
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34267
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpo... Read more
Affected Products : worldserver- EPSS Score: %73.90
- Published: Dec. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51035
TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.... Read more
- EPSS Score: %0.17
- Published: Dec. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24377
The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.... Read more
Affected Products : cycle-import-check- EPSS Score: %4.10
- Published: Dec. 14, 2022
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2019-10276
Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrated by a .php file with the image/jpeg content type.... Read more
Affected Products : razor- EPSS Score: %0.36
- Published: Mar. 29, 2019
- Modified: Nov. 21, 2024