Latest CVE Feed
-
9.8
CRITICALCVE-2021-25032
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the option... Read more
Affected Products : capabilities- EPSS Score: %56.03
- Published: Jan. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-8611
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of the argument customer leads to sql injection. The attack... Read more
Affected Products : tailoring_management_system- Published: Sep. 09, 2024
- Modified: Sep. 18, 2024
-
9.8
CRITICALCVE-2024-45824
CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link... Read more
Affected Products : factorytalk_view- Published: Sep. 12, 2024
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2020-4877
IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 could be vulnerable to unauthorized modifications by using public fields in public classes. IBM X-Force ID: 190843.... Read more
- EPSS Score: %0.35
- Published: Jan. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-42505
Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitati... Read more
Affected Products : arubaos- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2024-8877
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.... Read more
- Published: Sep. 25, 2024
- Modified: Sep. 30, 2024
-
9.8
CRITICALCVE-2021-26618
An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code.... Read more
- EPSS Score: %0.42
- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0651
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication ... Read more
Affected Products : wp_statistics- EPSS Score: %45.55
- Published: Feb. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24605
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.... Read more
Affected Products : luocms- EPSS Score: %0.25
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48223
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.... Read more
Affected Products : funadmin- Published: Oct. 25, 2024
- Modified: Oct. 31, 2024
-
9.8
CRITICALCVE-2024-39205
An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a crafted HTTP request.... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2022-26189
TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.... Read more
- EPSS Score: %14.90
- Published: Mar. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48202
icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.... Read more
Affected Products : icecms- Published: Oct. 30, 2024
- Modified: Apr. 18, 2025
-
9.8
CRITICALCVE-2024-10914
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulat... Read more
Affected Products : dns-320_firmware dns-320 dns-320lw_firmware dns-320lw dns-325_firmware dns-325 dns-340l_firmware dns-340l- Published: Nov. 06, 2024
- Modified: Nov. 24, 2024
-
9.8
CRITICALCVE-2024-10996
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/process_category_edit.php. The manipulation of the argument cat leads to sql injection. It is p... Read more
- Published: Nov. 08, 2024
- Modified: Nov. 13, 2024
-
9.8
CRITICALCVE-2024-10547
The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attacker... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2022-27862
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.... Read more
Affected Products : vikbooking_hotel_booking_engine_\&_property_management_system_plugin- EPSS Score: %1.17
- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21541
Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the ... Read more
Affected Products : dom-iterator- Published: Nov. 13, 2024
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2024-11244
A vulnerability classified as critical was found in code-projects Farmacia 1.0. This vulnerability affects unknown code of the file /editar-cliente.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The ... Read more
- Published: Nov. 15, 2024
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2024-11257
A vulnerability classified as critical has been found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. It is possible... Read more
Affected Products : beauty_parlour_management_system- Published: Nov. 15, 2024
- Modified: Nov. 19, 2024