Latest CVE Feed
-
9.8
CRITICALCVE-2023-29129
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.4.0), Mendi... Read more
Affected Products : saml- EPSS Score: %0.07
- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-1187
Bitlbee does not drop extra group privileges correctly in unix.c... Read more
Affected Products : bitlbee- EPSS Score: %0.43
- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-7913
A vulnerability was found in itsourcecode Billing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /addclient1.php. The manipulation of the argument lname/fname/mi/address/contact/meterReader leads to sql i... Read more
Affected Products : billing_system- Published: Aug. 18, 2024
- Modified: Aug. 19, 2024
-
9.8
CRITICALCVE-2018-15531
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.... Read more
- EPSS Score: %18.99
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2924
A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this issue is some unknown functionality of the file /admin/reportupload.aspx. The manipulation of the argument files[] leads to unrestricte... Read more
- EPSS Score: %5.72
- Published: May. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-1000453
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.98
- Published: Jan. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10752
Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.... Read more
Affected Products : sequelize- EPSS Score: %0.43
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-6948
A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password.... Read more
Affected Products : hashbrown_cms- EPSS Score: %3.28
- Published: Jan. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24240
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.... Read more
Affected Products : aceweb_online_portal- EPSS Score: %0.65
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32020
Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via ip/car-rental-management-system/admin/ajax.php?action=save_settings.... Read more
Affected Products : car_rental_management_system- EPSS Score: %0.97
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25237
Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no pr... Read more
Affected Products : bonita_web- EPSS Score: %91.98
- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10866
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.... Read more
- EPSS Score: %18.10
- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-4633
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in t... Read more
Affected Products : koha- EPSS Score: %4.18
- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45603
Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through ... Read more
Affected Products : user_submitted_posts- EPSS Score: %2.16
- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48388
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.... Read more
- EPSS Score: %0.65
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40954
A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remo... Read more
Affected Products : dynamic_progress_bar- EPSS Score: %0.62
- Published: Dec. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48417
Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application... Read more
- EPSS Score: %0.06
- Published: Dec. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7206
HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.... Read more
Affected Products : nagios-plugins-hpilo- EPSS Score: %1.04
- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46386
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.... Read more
Affected Products : mcms- EPSS Score: %6.40
- Published: Jan. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15839
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.... Read more
- EPSS Score: %51.10
- Published: Aug. 28, 2018
- Modified: Nov. 21, 2024