Latest CVE Feed
-
9.8
CRITICALCVE-2023-26793
libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.... Read more
Affected Products : libmodbus- Published: May. 01, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2020-16165
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.... Read more
- EPSS Score: %0.24
- Published: Jul. 30, 2020
- Modified: Jun. 03, 2025
-
9.8
CRITICALCVE-2023-50434
emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This can be triggered by a remote adversary that can send DNS requests to the emdns server. The im... Read more
Affected Products :- Published: Apr. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37181
72crm 9.0 has an Arbitrary file upload vulnerability.... Read more
Affected Products : wukong_crm- EPSS Score: %0.38
- Published: Aug. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4851
A vulnerability has been found in IBOS OA 4.5.5 and classified as critical. This vulnerability affects unknown code of the file ?r=dashboard/position/edit&op=member. The manipulation leads to sql injection. The attack can be initiated remotely. The exploi... Read more
Affected Products : ibos- EPSS Score: %0.04
- Published: Sep. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37112
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php... Read more
- EPSS Score: %0.25
- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29805
A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attackers to execute arbitrary code via a crafted XML payload.... Read more
Affected Products : fishbowl- EPSS Score: %10.06
- Published: Aug. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-32161
jizhiCMS 2.5 suffers from a File upload vulnerability.... Read more
Affected Products : jizhicms- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-20365
Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-19180
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php... Read more
Affected Products : yunucms- EPSS Score: %0.78
- Published: Nov. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17334
An issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in the svgGetNextPathField function in svg_string.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact bec... Read more
Affected Products : libsvg2- EPSS Score: %0.86
- Published: Sep. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1999019
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a sim... Read more
Affected Products : chamilo_lms- EPSS Score: %1.77
- Published: Jul. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21944
Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This ... Read more
Affected Products : imagegear- EPSS Score: %0.30
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17383
SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.... Read more
Affected Products : collection_factory- EPSS Score: %3.03
- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37090
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID.... Read more
- EPSS Score: %0.44
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2653
A vulnerability classified as critical was found in SourceCodester Lost and Found Information System 1.0. Affected by this vulnerability is an unknown functionality of the file items/index.php. The manipulation of the argument cid leads to sql injection. ... Read more
Affected Products : lost_and_found_information_system- EPSS Score: %0.05
- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34531
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.... Read more
Affected Products : dedecms- EPSS Score: %29.73
- Published: Jul. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-9107
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a univ... Read more
Affected Products : manageengine_opmanager- EPSS Score: %1.66
- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2020-29312
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpa... Read more
Affected Products : zend_framework- EPSS Score: %1.87
- Published: Apr. 04, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2023-26858
SQL injection vulnerability found in PrestaSHp faqs v.3.1.6 allows a remote attacker to escalate privileges via the faqsBudgetModuleFrontController::displayAjaxGenerateBudget component.... Read more
Affected Products : frequently_asked_questions_page- EPSS Score: %0.22
- Published: Mar. 31, 2023
- Modified: Feb. 18, 2025