Latest CVE Feed
-
9.8
CRITICALCVE-2024-12951
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the file /add_personal_details.php. The manipulation of the argument profile leads to unrestricted upload. It is... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 26, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-12944
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signin.php. The manipulation of the argument u/p leads to sql injection. The attack... Read more
- Published: Dec. 26, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-12964
A vulnerability was found in 1000 Projects Daily College Class Work Report Book 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation of the argument user leads to sql injection. It is possible to i... Read more
Affected Products : daily_college_class_work_report_book- Published: Dec. 26, 2024
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2024-12935
A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulnerability affects unknown code of the file editItemForm.php. The manipulation of the argument record leads to sql injection. The attack can be initiated rem... Read more
Affected Products : simple_admin_panel- Published: Dec. 26, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-12922
The Altair theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check within functions.php in all versions up to, and including, 5.2.4. This makes it possible for unauthen... Read more
Affected Products : altair- Published: Mar. 19, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-12968
A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. Affected by this vulnerability is the function edit_jobpost of the file /_parse/_all_edits.php. The manipulation of the argument jobtype leads to sql injection. The att... Read more
- Published: Dec. 26, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2010-4660
Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..... Read more
Affected Products : statusnet- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-12860
The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a u... Read more
Affected Products : carspot- Published: Feb. 18, 2025
- Modified: Feb. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2022-24112
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port ... Read more
Affected Products : apisix- Actively Exploited
- Published: Feb. 11, 2022
- Modified: Mar. 06, 2025
-
9.8
CRITICALCVE-2024-12899
A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/course_action.php. The manipulation of the argument course_code leads to sql... Read more
Affected Products : attendance_tracking_management_system- Published: Dec. 23, 2024
- Modified: Jan. 08, 2025
-
9.8
CRITICALCVE-2018-5187
Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird... Read more
- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2010-4533
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.... Read more
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25235
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.... Read more
Affected Products : fedora zfs_storage_appliance_kit debian_linux http_server sinema_remote_connect_server libexpat- Published: Feb. 16, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-12827
The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.6. This is due to the plugin not properly checking for an empty token value prior to res... Read more
Affected Products : dwt_listing- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2021-39214
mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a requ... Read more
Affected Products : mitmproxy- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26496
In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.... Read more
- Published: Mar. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-15027
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attempts. This was patched in 2020.7 and in a hotfix for 2019.12.... Read more
- Published: Jul. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-12824
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.2. This is due to the plugin not properly checking for an empty token value prior updating their... Read more
Affected Products :- Published: Mar. 01, 2025
- Modified: Mar. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-1567
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticate... Read more
Affected Products : royal_elementor_addons- Published: May. 02, 2024
- Modified: Jan. 08, 2025
-
9.8
CRITICALCVE-2024-12727
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchang... Read more
- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024