Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2022-36273

    Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.... Read more

    Affected Products : ac9_firmware ac9
    • EPSS Score: %18.36
    • Published: Aug. 16, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-2682

    A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/ping.cgi of the component Mini_HTTPD. The manipulation of the argument address with the input ;id;uname${I... Read more

    Affected Products : caton_live
    • EPSS Score: %0.18
    • Published: May. 12, 2023
    • Modified: Jan. 24, 2025
  • 9.8

    CRITICAL
    CVE-2023-26311

    A remote code execution vulnerability in the webview component of OPPO Store app. ... Read more

    Affected Products : oppo_store
    • EPSS Score: %1.49
    • Published: Aug. 10, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-36344

    An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted fi... Read more

    • EPSS Score: %0.71
    • Published: Aug. 16, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-41657

    Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files, which could be... Read more

    Affected Products : infrasuite_device_master
    • EPSS Score: %27.48
    • Published: Oct. 31, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-26921

    OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd.... Read more

    Affected Products : ag550qcn_firmware ag550qcn
    • EPSS Score: %1.81
    • Published: Apr. 04, 2023
    • Modified: Feb. 13, 2025
  • 9.8

    CRITICAL
    CVE-2023-26978

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.... Read more

    Affected Products : a7100ru_firmware a7100ru
    • EPSS Score: %1.45
    • Published: Apr. 07, 2023
    • Modified: Feb. 12, 2025
  • 9.8

    CRITICAL
    CVE-2023-27016

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.... Read more

    Affected Products : ac10_firmware ac10
    • EPSS Score: %0.32
    • Published: Apr. 07, 2023
    • Modified: Feb. 12, 2025
  • 9.8

    CRITICAL
    CVE-2023-27018

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.... Read more

    Affected Products : ac10_firmware ac10
    • EPSS Score: %0.12
    • Published: Apr. 07, 2023
    • Modified: Feb. 12, 2025
  • 9.8

    CRITICAL
    CVE-2023-27040

    Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.... Read more

    Affected Products : simple_image_gallery_web_app
    • EPSS Score: %1.70
    • Published: Mar. 16, 2023
    • Modified: Feb. 26, 2025
  • 9.8

    CRITICAL
    CVE-2023-27203

    Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.... Read more

    Affected Products : best_pos_management_system
    • EPSS Score: %0.07
    • Published: Mar. 09, 2023
    • Modified: Mar. 05, 2025
  • 9.8

    CRITICAL
    CVE-2022-36452

    A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A successful exploit could allow an attacker to execute arbitrary code within the context of the appli... Read more

    Affected Products : micollab
    • EPSS Score: %1.90
    • Published: Oct. 25, 2022
    • Modified: May. 07, 2025
  • 9.8

    CRITICAL
    CVE-2022-36663

    Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.... Read more

    Affected Products : oxauth
    • EPSS Score: %8.46
    • Published: Sep. 06, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-36711

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bookdetails.php.... Read more

    Affected Products : library_management_system
    • EPSS Score: %0.11
    • Published: Aug. 30, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2017-6532

    Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 have cleartext credentials in /mib.db.... Read more

    • EPSS Score: %0.54
    • Published: Jul. 20, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2022-37002

    The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.... Read more

    Affected Products : emui harmonyos magic_ui
    • EPSS Score: %0.25
    • Published: Aug. 10, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-37057

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.... Read more

    Affected Products : go-rt-ac750_firmware go-rt-ac750
    • EPSS Score: %65.08
    • Published: Aug. 28, 2022
    • Modified: Jan. 06, 2025
  • 9.8

    CRITICAL
    CVE-2022-37061

    All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php end... Read more

    Affected Products : flir_ax8_firmware flir_ax8
    • EPSS Score: %91.53
    • Published: Aug. 18, 2022
    • Modified: Mar. 31, 2025
  • 9.8

    CRITICAL
    CVE-2022-37258

    Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName variable in npm-convert.js.... Read more

    Affected Products : steal
    • EPSS Score: %0.14
    • Published: Sep. 16, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-37298

    Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes t... Read more

    Affected Products : shinken_monitoring
    • EPSS Score: %44.43
    • Published: Oct. 20, 2022
    • Modified: May. 08, 2025
Showing 20 of 291158 Results