Latest CVE Feed
-
9.8
CRITICALCVE-2024-23058
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069Cfg function.... Read more
- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23061
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setScheduleCfg function.... Read more
- Published: Jan. 11, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-22988
ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.... Read more
Affected Products : zkbio_wdms- Published: Feb. 23, 2024
- Modified: Jun. 07, 2025
-
9.8
CRITICALCVE-2020-22597
An issue in Jerrscript- project Jerryscrip v. 2.3.0 allows a remote attacker to execute arbitrary code via the ecma_builtin_array_prototype_object_slice parameter.... Read more
Affected Products : jerryscript- Published: Jul. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-6094
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system... Read more
- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22617
Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.... Read more
Affected Products : ardour- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22249
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plu... Read more
Affected Products : phplist- Published: Jul. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22633
Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request.... Read more
Affected Products :- Published: Apr. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22225
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.... Read more
Affected Products : fundraising_script- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22632
Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request.... Read more
Affected Products :- Published: Apr. 26, 2024
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2020-22203
SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php.... Read more
Affected Products : phpcms- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22206
SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.... Read more
Affected Products : ecshop- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22441
HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.... Read more
Affected Products : cray_parallel_application_launch_service- Published: Jun. 13, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2019-18658
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /etc/passwd, or to execute a denial of service (DoS) via a ... Read more
Affected Products : helm- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19012
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remot... Read more
- Published: Nov. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22205
SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php.... Read more
Affected Products : ecshop- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-28545
Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.... Read more
- Published: Mar. 26, 2024
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2024-22391
A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger t... Read more
- Published: Apr. 25, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2020-22153
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.... Read more
Affected Products : fuel_cms- Published: Jul. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22079
Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.... Read more
- Published: Oct. 29, 2021
- Modified: Nov. 21, 2024