Latest CVE Feed
-
9.8
CRITICALCVE-2005-0496
Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.... Read more
Affected Products : network_backup- Published: Feb. 21, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-10195
A vulnerability was found in Tecno 4G Portable WiFi TR118 V008-20220830. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /goform/goform_get_cmd_process of the component SMS Check. The manipulation o... Read more
- Published: Oct. 20, 2024
- Modified: Oct. 24, 2024
-
9.8
CRITICALCVE-2019-9791
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacemen... Read more
- Published: Apr. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19646
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.... Read more
- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0289
A vulnerability classified as critical was found in Kashipara Food Management System 1.0. This vulnerability affects unknown code of the file stock_entry_submit.php. The manipulation of the argument itemype leads to sql injection. The attack can be initia... Read more
Affected Products : food_management_system- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9631
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.... Read more
- Published: Mar. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9552
Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.... Read more
Affected Products : eloan- Published: Mar. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9566
FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.... Read more
Affected Products : flarumchina- Published: Mar. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11117
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Wired Infrastructur... Read more
Affected Products : ipq6018_firmware ipq8064_firmware ipq8074_firmware qca9980_firmware ipq4019_firmware qca9531_firmware qca4531_firmware ipq4019 ipq6018 ipq8064 +4 more products- Published: Sep. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9365
In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: A... Read more
Affected Products : android- Published: Sep. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10163
A vulnerability was found in SourceCodester Sentiment Based Movie Rating System 1.0. It has been classified as critical. Affected is an unknown function of the file /msrps/movie_details.php. The manipulation of the argument id leads to sql injection. It i... Read more
Affected Products : sentiment_based_movie_rating_system- Published: Oct. 20, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2019-9215
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.... Read more
- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9201
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to traverse all directories.... Read more
- Published: Feb. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9217
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. Its User Interface has a Misrepresentation of Critical Information.... Read more
Affected Products : gitlab- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9204
SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.... Read more
Affected Products : incident_manager- Published: Mar. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9163
The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.... Read more
Affected Products : command_client- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.... Read more
Affected Products : elfinder- Published: Feb. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9124
An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank password.... Read more
- Published: Feb. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9099
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate Do... Read more
Affected Products : mb3170_firmware mb3270_firmware mb3180_firmware mb3280_firmware mb3480_firmware mb3660_firmware mb3170 mb3270 mb3180 mb3280 +2 more products- Published: Mar. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-2418
A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view_order.php. The manipulation of the argument id leads to sql injectio... Read more
- Published: Mar. 13, 2024
- Modified: Feb. 18, 2025