Latest CVE Feed
-
9.4
CRITICALCVE-2022-0942
Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.... Read more
Affected Products : showdoc- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-1330
stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss .... Read more
Affected Products : fullpage- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-1592
Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...... Read more
Affected Products : scout- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-1682
Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser... Read more
Affected Products : facturascripts- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2021-27442
The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.... Read more
Affected Products : cmt-svr-100_firmware cmt-svr-102_firmware cmt-svr-200_firmware cmt-svr-202_firmware cmt-g01_firmware cmt-g02_firmware cmt-g03_firmware cmt-g04_firmware cmt3071_firmware cmt3072_firmware +22 more products- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2016-5843
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters.... Read more
Affected Products : faq- Published: Sep. 17, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2016-2296
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2022-3224
Misinterpretation of Input in GitHub repository ionicabizau/parse-url prior to 8.1.0.... Read more
Affected Products : parse-url- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2016-1000112
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin... Read more
Affected Products : contus-video-comments- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2025-54071
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. In versions 4.0.0-beta.3 and below, an authenticated arbitrary file write vulnerability exists in the /api/saves endpoint. This ... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Path Traversal
-
9.4
CRITICALCVE-2025-34152
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without reboo... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.4
HIGHCVE-2016-8491
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
9.4
HIGHCVE-2021-38917
IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and write arbitrary host system memory through a series of carefully crafted service procedures. IBM X-Force ID: 210018.... Read more
Affected Products : powervm_hypervisor- Published: Dec. 10, 2021
- Modified: Nov. 21, 2024
-
9.4
HIGHCVE-2021-39635
ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions... Read more
Affected Products : android- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2023-6353
Tyler Technologies Civil and Criminal Electronic Filing allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the Upload.aspx 'enky' parameter. ... Read more
Affected Products : court_case_management_plus- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2023-6354
Tyler Technologies Magistrate Court Case Management Plus allows an unauthenticated, remote attacker to upload, delete, and view files by manipulating the PDFViewer.aspx 'filename' parameter. ... Read more
Affected Products : court_case_management_plus- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-41271
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform... Read more
Affected Products : netweaver_process_integration- Published: Dec. 13, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2022-23555
authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a diffe... Read more
Affected Products : authentik- Published: Dec. 28, 2022
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2018-14786
Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prior are affected by an improper authentication vulnerability where the software does not perform authentica... Read more
- Published: Aug. 23, 2018
- Modified: Nov. 21, 2024
-
9.4
CRITICALCVE-2023-1898
Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session.... Read more
- Published: Jun. 12, 2023
- Modified: Nov. 21, 2024