Latest CVE Feed
-
9.8
CRITICALCVE-2023-40069
OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-F1167ACF all vers... Read more
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0... Read more
Affected Products : jquery_file_upload- Published: Oct. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8784
FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory corruption and probably even a remote code execution.... Read more
- Published: Nov. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40042
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code.... Read more
- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-8775
A vulnerability was found in Qiyuesuo Eelectronic Signature Platform up to 4.34 and classified as critical. Affected by this issue is the function execute of the file /api/code/upload of the component Scheduled Task Handler. The manipulation of the argume... Read more
Affected Products : electronic_signature- Published: Aug. 09, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-40010
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in realmag777 HUSKY – Products Filter for WooCommerce Professional.This issue affects HUSKY – Products Filter for WooCommerce Professional: from n/a through... Read more
Affected Products : husky_-_products_filter_professional_for_woocommerce- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3975
OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.... Read more
Affected Products : drawio- Published: Jul. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8092
Mautic before 2.13.0 allows CSV injection.... Read more
- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3804
A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file /Service/FileHandler.ashx. The manipulation of the argument userFile leads to unrest... Read more
Affected Products : flash_flood_disaster_monitoring_and_warning_system- Published: Jul. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3801
A vulnerability was found in IBOS OA 4.5.5. It has been declared as critical. Affected by this vulnerability is the function actionEdit of the file ?r=officialdoc/officialdoc/edit of the component Mobile Notification Handler. The manipulation leads to sql... Read more
Affected Products : ibos- Published: Jul. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3799
A vulnerability was found in IBOS OA 4.5.5 and classified as critical. This issue affects some unknown processing of the file ?r=article/category/del of the component Delete Category Handler. The manipulation leads to sql injection. The attack may be init... Read more
Affected Products : ibos- Published: Jul. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7247
An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can overflow a buffer, leading potentially to arbitrary code execution or possibly unspecified other impact.... Read more
Affected Products : leptonica- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8018
In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ig... Read more
Affected Products : ignite- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6916
In FreeBSD before 11.1-STABLE, 11.1-RELEASE-p7, 10.4-STABLE, 10.4-RELEASE-p7, and 10.3-RELEASE-p28, the kernel does not properly validate IPsec packets coming from a trusted host. Additionally, a use-after-free vulnerability exists in the IPsec AH handlin... Read more
Affected Products : freebsd- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3722
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 a... Read more
Affected Products : aura_device_services- Published: Jul. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3657
A vulnerability, which was classified as critical, has been found in SourceCodester AC Repair and Services System 1.0. This issue affects some unknown processing of the file Master.php?f=save_book of the component HTTP POST Request Handler. The manipulati... Read more
Affected Products : ac_repair_and_services_system- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8021
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.... Read more
Affected Products : superset- Published: Nov. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3638
In GeoVision GV-ADR2701 cameras, an attacker could edit the login response to access the web application. ... Read more
- Published: Jul. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3617
A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation of the argument username leads to sql in... Read more
- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5159
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulner... Read more
Affected Products : firefox firefox_esr thunderbird ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_eus +2 more products- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024