Latest CVE Feed
-
9.8
CRITICALCVE-2019-8341
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION CO... Read more
- EPSS Score: %22.01
- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12149
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowin... Read more
Affected Products : jboss_enterprise_application_platform- Actively Exploited
- EPSS Score: %94.31
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-27396
FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS proto... Read more
- EPSS Score: %1.54
- Published: Jun. 19, 2023
- Modified: Dec. 24, 2024
-
9.8
CRITICALCVE-2023-27394
Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and Alarms... Read more
- EPSS Score: %4.37
- Published: Mar. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-7743
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-fi... Read more
- EPSS Score: %1.45
- Published: Feb. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-7690
In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from process memory for the lifetime of the process, even after the user disconnects from the remote SSH server. This affects Passwordless Authen... Read more
Affected Products : mobaxterm- EPSS Score: %0.46
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-7238
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.... Read more
Affected Products : nexus- Actively Exploited
- EPSS Score: %94.02
- Published: Mar. 21, 2019
- Modified: Mar. 07, 2025
-
9.8
CRITICALCVE-2023-27250
Online Book Store Project v1.0 is vulnerable to SQL Injection via /bookstore/bookPerPub.php.... Read more
Affected Products : online_book_store_project- EPSS Score: %0.27
- Published: Mar. 16, 2023
- Modified: Feb. 26, 2025
-
9.8
CRITICALCVE-2023-27207
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.... Read more
Affected Products : online_pizza_ordering_system- EPSS Score: %0.07
- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27232
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wanStrategy parameter at /setting/setWanIeCfg.... Read more
- EPSS Score: %1.58
- Published: Mar. 28, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2023-27203
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.... Read more
Affected Products : best_pos_management_system- EPSS Score: %0.07
- Published: Mar. 09, 2023
- Modified: Mar. 05, 2025
-
9.8
CRITICALCVE-2023-27214
Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.... Read more
Affected Products : online_student_management_system- EPSS Score: %0.07
- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27168
An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.... Read more
Affected Products : write-back_manager- EPSS Score: %0.24
- Published: Jan. 19, 2024
- Modified: Jun. 02, 2025
-
9.8
CRITICALCVE-2023-27133
TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. This may enable privilege escalation if a different local user modifies a file. NOTE: CVE-2023-31067 and CV... Read more
Affected Products : tsplus_remote_work- EPSS Score: %0.09
- Published: Oct. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27113
pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at project.php.... Read more
Affected Products : pearprojectapi- Published: Jan. 21, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2019-6609
Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0.0-14.1.0.1, 13.0.0-13.1.1.3, and 12... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +27 more products- EPSS Score: %0.47
- Published: Apr. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27100
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.... Read more
- EPSS Score: %2.25
- Published: Mar. 22, 2023
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2022-26268
Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.... Read more
Affected Products : xiaohuanxiong- EPSS Score: %0.23
- Published: Mar. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27195
Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve the last registration access code and use this access code to register a valid account. via a PUT /inc/tm_ajax.msw request. If the access... Read more
Affected Products :- Published: Nov. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27033
Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontController::initContent().... Read more
Affected Products : cdesigner- EPSS Score: %0.10
- Published: Apr. 07, 2023
- Modified: Feb. 12, 2025