Latest CVE Feed
-
9.3
CRITICALCVE-2022-31541
The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : barry_voice_assistant- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31549
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : helm-flask-celery- EPSS Score: %0.43
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31525
The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : deep_learning_studio- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31551
The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : flask-mongo-skel- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31560
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : photo_tag- EPSS Score: %0.44
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31562
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : internshipsystem- EPSS Score: %0.44
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31580
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : caretakerr-api- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31585
The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : home__internet- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2025-40628
SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update and delete databases via the “d” parameter in the “/article.php” endpoint.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-39395
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS allows SQL Injection.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-48122
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows SQL Injection. This issue affects Spreadsheet Price Changer... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-40656
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter in /administer/node-selection/data.asp.... Read more
Affected Products :- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
-
9.3
CRITICALCVE-2025-40657
A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform parameter in /modules/forms/collectform.asp.... Read more
Affected Products :- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-34022
A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The /common/get_file.php script in ... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
9.3
CRITICALCVE-2025-52834
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in favethemes Homey allows SQL Injection. This issue affects Homey: from n/a through 2.4.5.... Read more
Affected Products : homey- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2022-33219
Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.... Read more
Affected Products : qam8295p_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware sa6155p_firmware sa8145p_firmware sa8150p_firmware sa8155p_firmware +38 more products- EPSS Score: %0.10
- Published: Jan. 09, 2023
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2025-54120
PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Although the log file... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
9.3
CRITICALCVE-2016-15044
A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sending a specially cr... Read more
Affected Products :- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2023-1244
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6.... Read more
Affected Products : answer- EPSS Score: %0.09
- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2013-10034
An unrestricted file upload vulnerability exists in Kaseya KServer versions prior to 6.3.0.2. The uploadImage.asp endpoint allows unauthenticated users to upload files to arbitrary paths via a crafted filename parameter in a multipart/form-data POST reque... Read more
Affected Products :- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authentication