Latest CVE Feed
-
9.3
HIGHCVE-2021-21956
A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead to potential arbitrary command execution. An attacker can provide a malicious file to trigger this vulner... Read more
Affected Products : imunify360- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-9832
There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force attack to gain unauthorized access to the ventilator, and then make changes to ... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
9.3
CRITICALCVE-2024-48971
The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician p... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
9.3
CRITICALCVE-2024-52528
Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intended restrictions.... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
9.3
CRITICALCVE-2024-38643
A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerabilit... Read more
Affected Products : notes_station_3- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
9.3
CRITICALCVE-2024-52958
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.... Read more
Affected Products :- Published: Nov. 27, 2024
- Modified: Nov. 27, 2024
-
9.3
CRITICALCVE-2024-54221
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roninwp FAT Services Booking.This issue affects FAT Services Booking: from n/a through 5.6.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
9.3
CRITICALCVE-2024-54143
openwrt/asu is an image on demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By explo... Read more
Affected Products : openwrt- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
9.3
CRITICALCVE-2023-43556
Memory corruption in Hypervisor when platform information mentioned is not aligned.... Read more
Affected Products : qam8295p_firmware qca6391_firmware qca6574au_firmware qca6696_firmware sa8295p_firmware wcd9380_firmware wcd9385_firmware wcn3988_firmware wsa8810_firmware wsa8815_firmware +142 more products- Published: Jun. 03, 2024
- Modified: Aug. 11, 2025
-
9.3
CRITICALCVE-2022-31511
The AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : equanimity- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31521
The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : mosaic- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31522
The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : karaokey- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31534
The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : pythonweb- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31549
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : helm-flask-celery- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31551
The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : flask-mongo-skel- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31562
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : internshipsystem- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31580
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : caretakerr-api- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2025-39395
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS allows SQL Injection.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-48122
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows SQL Injection. This issue affects Spreadsheet Price Changer... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-40657
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp.... Read more
Affected Products :- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection