Latest CVE Feed
-
9.8
CRITICALCVE-2023-24020
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection, allowing multiple attempts to force a login. ... Read more
- EPSS Score: %0.01
- Published: Jan. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24152
A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.... Read more
- EPSS Score: %1.77
- Published: Feb. 03, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2022-34045
Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.... Read more
- EPSS Score: %35.89
- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34115
DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.... Read more
- EPSS Score: %0.34
- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24585
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.... Read more
- EPSS Score: %0.23
- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34331
After performing a sequence of Power FW950, FW1010 maintenance operations a SRIOV network adapter can be improperly configured leading to desired VEPA configuration being disabled. IBM X-Force ID: 229695.... Read more
Affected Products : powervm_hypervisor- EPSS Score: %0.05
- Published: Nov. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5987
SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid paramet... Read more
Affected Products : social_pinboard- EPSS Score: %1.49
- Published: Feb. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34379
Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could potentially exploit this vulnerability to gain unauthorized access to the system... Read more
Affected Products : cloudlink- EPSS Score: %0.19
- Published: Sep. 01, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3439
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.... Read more
Affected Products : rdiffweb- EPSS Score: %0.39
- Published: Oct. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24773
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.... Read more
Affected Products : funadmin- EPSS Score: %0.09
- Published: Mar. 08, 2023
- Modified: Mar. 05, 2025
-
9.8
CRITICALCVE-2022-3998
A vulnerability, which was classified as critical, was found in MonikaBrzica scm. This affects an unknown part of the file uredi_korisnika.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The... Read more
Affected Products : scm- EPSS Score: %0.05
- Published: Nov. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-8378
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials.... Read more
Affected Products : jenesys_bas_bridge- EPSS Score: %0.50
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2008-5784
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.... Read more
Affected Products : v3_chat_profiles_dating_script- EPSS Score: %3.38
- Published: Dec. 31, 2008
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2022-40138
An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only exploitable in ca... Read more
Affected Products : hermes- EPSS Score: %0.40
- Published: Oct. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34839
Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.... Read more
Affected Products : wp_oauth2_server- EPSS Score: %0.52
- Published: Jul. 22, 2022
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2023-25233
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.... Read more
- EPSS Score: %0.12
- Published: Feb. 27, 2023
- Modified: Mar. 10, 2025
-
9.8
CRITICALCVE-2022-3485
In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device. ... Read more
- EPSS Score: %0.53
- Published: Dec. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25560
DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, verifying credentials, resetting them or requesting access tokens, crafts multiple JSON strings using format strings with user-controlled... Read more
Affected Products : datahub- EPSS Score: %0.16
- Published: Feb. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-21121
Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.... Read more
Affected Products : kliqqi_cms- EPSS Score: %0.30
- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35490
Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess login credentials. After a configurable amount of attempts, users are invalidated and logins prevented. An attacker might work around t... Read more
Affected Products : zammad- EPSS Score: %0.41
- Published: Aug. 08, 2022
- Modified: Nov. 21, 2024