Latest CVE Feed
-
9.8
CRITICALCVE-2024-12987
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the ... Read more
- Actively Exploited
- Published: Dec. 27, 2024
- Modified: May. 16, 2025
-
9.8
CRITICALCVE-2024-12976
A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /staff.php. The manipulation of the argument tel leads to sql injection. The att... Read more
Affected Products : hospital_management_system hospital_management_system hospital_management_system- Published: Dec. 27, 2024
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2024-13016
A vulnerability was found in PHPGurukul Maid Hiring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit-category.php. The manipulation of the argument editid leads to sql injection. It is possibl... Read more
Affected Products : maid_hiring_management_system- Published: Dec. 29, 2024
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2024-12953
A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected by this issue is some unknown functionality of the file /update_pd_process.php. The manipulation of the argument profile leads... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 26, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-12951
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the file /add_personal_details.php. The manipulation of the argument profile leads to unrestricted upload. It is... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 26, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-12944
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signin.php. The manipulation of the argument u/p leads to sql injection. The attack... Read more
- Published: Dec. 26, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-12964
A vulnerability was found in 1000 Projects Daily College Class Work Report Book 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation of the argument user leads to sql injection. It is possible to i... Read more
Affected Products : daily_college_class_work_report_book- Published: Dec. 26, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-12935
A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulnerability affects unknown code of the file editItemForm.php. The manipulation of the argument record leads to sql injection. The attack can be initiated rem... Read more
Affected Products : simple_admin_panel- Published: Dec. 26, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-12922
The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within functions.php in all versions up to, and including, 5.2.4. This makes it possible for unauthen... Read more
Affected Products : altair- Published: Mar. 19, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-12968
A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. Affected by this vulnerability is the function edit_jobpost of the file /_parse/_all_edits.php. The manipulation of the argument jobtype leads to sql injection. The att... Read more
- Published: Dec. 26, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2010-4660
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..... Read more
Affected Products : statusnet- EPSS Score: %0.42
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-12860
The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a u... Read more
Affected Products : carspot- Published: Feb. 18, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2022-24112
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port ... Read more
Affected Products : apisix- Actively Exploited
- EPSS Score: %94.34
- Published: Feb. 11, 2022
- Modified: Mar. 06, 2025
-
9.8
CRITICALCVE-2024-12899
A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/course_action.php. The manipulation of the argument course_code leads to sql... Read more
Affected Products : attendance_tracking_management_system- Published: Dec. 23, 2024
- Modified: Jan. 08, 2025
-
9.8
CRITICALCVE-2018-5187
Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird... Read more
- EPSS Score: %3.69
- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2010-4533
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.... Read more
- EPSS Score: %0.28
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25235
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.... Read more
Affected Products : fedora zfs_storage_appliance_kit debian_linux http_server sinema_remote_connect_server libexpat- EPSS Score: %13.32
- Published: Feb. 16, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-12827
The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.6. This is due to the plugin not properly checking for an empty token value prior to res... Read more
Affected Products : dwt_listing- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2021-39214
mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a requ... Read more
Affected Products : mitmproxy- EPSS Score: %0.19
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26496
In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.... Read more
- EPSS Score: %0.48
- Published: Mar. 06, 2022
- Modified: Nov. 21, 2024