Latest CVE Feed
-
9.8
CRITICALCVE-2022-23363
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php.... Read more
Affected Products : online_banking_system- EPSS Score: %0.24
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23402
The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00... Read more
- EPSS Score: %0.41
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36357
An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uint16_t "year" value, resulting in a type mismatch that can truncate a higher integer value to a smaller one, and bypass a timestamp chec... Read more
Affected Products : skiboot- EPSS Score: %0.20
- Published: Oct. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-36547
A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.... Read more
Affected Products : mara_cms- EPSS Score: %22.36
- Published: Oct. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23764
The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution.... Read more
- EPSS Score: %0.44
- Published: Aug. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23768
This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use this vulnerability to induce all attacks such as source code hijacking, remote control of the device.... Read more
- EPSS Score: %0.26
- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23880
An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.... Read more
Affected Products : taocms- EPSS Score: %0.81
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-23899
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.... Read more
Affected Products : mcms- EPSS Score: %0.23
- Published: Mar. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17479
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.... Read more
Affected Products : json_pattern_validator- EPSS Score: %0.63
- Published: Aug. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37153
ForgeRock Access Management (AM) before 7.0.2, when configured with Active Directory as the Identity Store, has an authentication-bypass issue.... Read more
Affected Products : access_management- EPSS Score: %0.63
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24150
Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebMan. This vulnerability allows attackers to execute arbitrary commands via the remoteIp parameter.... Read more
- EPSS Score: %9.14
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24239
ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.... Read more
Affected Products : aceweb_online_portal- EPSS Score: %0.72
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24313
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Product: Interactive Graphi... Read more
Affected Products : interactive_graphical_scada_system_data_server- EPSS Score: %4.70
- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-5212
Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.... Read more
Affected Products : open-xchange_appsuite- EPSS Score: %0.59
- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-36061
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.... Read more
Affected Products :- Published: Nov. 11, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2022-24568
Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.... Read more
- EPSS Score: %0.32
- Published: Feb. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24602
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.... Read more
Affected Products : luocms- EPSS Score: %0.25
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-17952
A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbitrary PHP code.... Read more
Affected Products : twothink- EPSS Score: %2.23
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24829
Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes this allows for an attacker to gain access to the application erroneously. The... Read more
Affected Products : garden- EPSS Score: %0.25
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32020
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.... Read more
Affected Products : freertos- EPSS Score: %0.30
- Published: May. 03, 2021
- Modified: Nov. 21, 2024