Latest CVE Feed
-
9.4
CRITICALCVE-2025-54062
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `/html/funcionario/profile_dependente.php` endpoint, specifically in th... Read more
Affected Products : wegia- Published: Jul. 17, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2025-34150
The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to command injection via the 'user' parameter. Input is processed unsafely during network setup, allowing attackers to execute arbitrary syste... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2012-10059
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitr... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.4
CRITICALCVE-2023-1834
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attackers unauthorized access to the devic... Read more
- EPSS Score: %0.24
- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2023-1897
Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controller.... Read more
- EPSS Score: %0.04
- Published: Jun. 12, 2023
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2023-1935
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.... Read more
Affected Products : roc809_firmware roc827_firmware roc809l_firmware roc827l_firmware dl8000_firmware dl8000 roc809 roc827 roc809l roc827l- EPSS Score: %0.02
- Published: Aug. 02, 2023
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2018-20577
Orange Livebox 00.96.320S devices allow cgi-bin/restore.exe, cgi-bin/firewall_SPI.exe, cgi-bin/setup_remote_mgmt.exe, cgi-bin/setup_pass.exe, and cgi-bin/upgradep.exe CSRF. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1... Read more
- EPSS Score: %0.14
- Published: Dec. 28, 2018
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2019-14063
Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infr... Read more
Affected Products : sa6155p_firmware ipq6018_firmware ipq8064_firmware ipq8074_firmware sdx55_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware qcs405_firmware +30 more products- EPSS Score: %0.24
- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2019-20696
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects WAC505 before V5.6.8.3 and WAC510 before V5.6.8.3.... Read more
- EPSS Score: %0.40
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-36980
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The spe... Read more
Affected Products : avalanche- EPSS Score: %2.58
- Published: Mar. 29, 2023
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2025-55293
Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite it with a new key. First sending a empty key bypasses 'if (p.public_key.size > 0) {', clearing the existing ... Read more
Affected Products : meshtastic_firmware- Published: Aug. 18, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-55299
VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an empty but not NULL password set, attackers can use this to login with an empty password. This is combined with ... Read more
Affected Products :- Published: Aug. 18, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authentication
-
9.4
CRITICALCVE-2025-30091
In Tiny MoxieManager PHP before 4.0.0, remote code execution can occur in the installer command. This vulnerability allows unauthenticated attackers to inject and execute arbitrary code. Attacker-controlled data to InstallCommand can be inserted into conf... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
9.4
HIGHCVE-2019-10550
Buffer Over-read when UE is trying to process the message received form the network without zero termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MD... Read more
Affected Products : sdx55_firmware sdm660_firmware sm8150_firmware msm8996au_firmware qcs605_firmware sdx24_firmware mdm9650_firmware msm8909w_firmware sdm429w_firmware sdx20_firmware +70 more products- EPSS Score: %0.24
- Published: Mar. 05, 2020
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2024-25521
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.... Read more
Affected Products : ruvaroa- Published: May. 08, 2024
- Modified: Apr. 17, 2025
-
9.4
CRITICALCVE-2024-25522
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_form_save.aspx.... Read more
Affected Products : ruvaroa- Published: May. 08, 2024
- Modified: Apr. 17, 2025
-
9.4
CRITICALCVE-2024-25524
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlanAttachDownLoad.aspx.... Read more
Affected Products : ruvaroa- Published: May. 08, 2024
- Modified: Apr. 17, 2025
-
9.4
HIGHCVE-2020-11191
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Sn... Read more
Affected Products : aqt1000_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware +942 more products- EPSS Score: %0.24
- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2018-14994
The Essential Phone Android device with a build fingerprint of essential/mata/mata:8.1.0/OPM1.180104.166/297:user/release-keys contains a pre-installed platform app with a package name of com.ts.android.hiddenmenu (versionName=1.0, platformBuildVersionNam... Read more
- EPSS Score: %0.29
- Published: Apr. 25, 2019
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2022-30713
Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.... Read more
- EPSS Score: %0.09
- Published: Jun. 07, 2022
- Modified: Nov. 21, 2024