Latest CVE Feed
-
9.8
CRITICALCVE-2024-28698
Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component.... Read more
Affected Products :- Published: Jul. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26794
Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.... Read more
Affected Products : frogcms- EPSS Score: %0.85
- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-7362
A vulnerability, which was classified as critical, has been found in SourceCodester Tracking Monitoring Management System 1.0. This issue affects some unknown processing of the file /manage_user.php. The manipulation of the argument id leads to sql inject... Read more
Affected Products : tracking_monitoring_management_system- Published: Aug. 01, 2024
- Modified: Aug. 09, 2024
-
9.8
CRITICALCVE-2021-41075
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.... Read more
Affected Products : manageengine_opmanager- EPSS Score: %36.35
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-7462
A vulnerability classified as critical has been found in TOTOLINK N350RT 9.3.5u.6139_B20201216. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid leads to buffer overflow. It is possible to init... Read more
- Published: Aug. 05, 2024
- Modified: Aug. 15, 2024
-
9.8
CRITICALCVE-2021-43202
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.... Read more
Affected Products : teamcity- EPSS Score: %0.00
- Published: Nov. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43834
eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such ... Read more
Affected Products : elabftw- EPSS Score: %0.32
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25032
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the option... Read more
Affected Products : capabilities- EPSS Score: %56.03
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-8611
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of the argument customer leads to sql injection. The attack... Read more
Affected Products : tailoring_management_system- Published: Sep. 09, 2024
- Modified: Sep. 18, 2024
-
9.8
CRITICALCVE-2024-45824
CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link... Read more
Affected Products : factorytalk_view- Published: Sep. 12, 2024
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2020-4877
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.... Read more
- EPSS Score: %0.35
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-42505
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitati... Read more
Affected Products : arubaos- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-8877
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.... Read more
- Published: Sep. 25, 2024
- Modified: Sep. 30, 2024
-
9.8
CRITICALCVE-2021-26618
An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code.... Read more
- EPSS Score: %0.42
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0651
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication ... Read more
Affected Products : wp_statistics- EPSS Score: %45.55
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24605
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.... Read more
Affected Products : luocms- EPSS Score: %0.25
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48223
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-39205
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2022-26189
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.... Read more
- EPSS Score: %14.90
- Published: Mar. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48202
icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.... Read more
Affected Products : icecms- Published: Oct. 30, 2024
- Modified: Apr. 18, 2025