Latest CVE Feed
-
9.3
CRITICALCVE-2024-52528
Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does not properly validate auth tokens, which allows attackers to bypass intended restrictions.... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
9.3
CRITICALCVE-2024-38643
A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerabilit... Read more
Affected Products : notes_station_3- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
9.3
CRITICALCVE-2024-52958
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.... Read more
Affected Products :- Published: Nov. 27, 2024
- Modified: Nov. 27, 2024
-
9.3
CRITICALCVE-2024-54221
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roninwp FAT Services Booking.This issue affects FAT Services Booking: from n/a through 5.6.... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
9.3
CRITICALCVE-2024-54143
openwrt/asu is an image on demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By explo... Read more
Affected Products : openwrt- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
9.3
CRITICALCVE-2023-43556
Memory corruption in Hypervisor when platform information mentioned is not aligned.... Read more
Affected Products : qam8295p_firmware qca6391_firmware qca6574au_firmware qca6696_firmware sa8295p_firmware wcd9380_firmware wcd9385_firmware wcn3988_firmware wsa8810_firmware wsa8815_firmware +142 more products- Published: Jun. 03, 2024
- Modified: Aug. 11, 2025
-
9.3
CRITICALCVE-2022-31511
The AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : equanimity- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31514
The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : fan_platform- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31521
The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : mosaic- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31522
The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : karaokey- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31534
The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : pythonweb- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31541
The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : barry_voice_assistant- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31549
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : helm-flask-celery- EPSS Score: %0.43
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31525
The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : deep_learning_studio- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31551
The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : flask-mongo-skel- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31560
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : photo_tag- EPSS Score: %0.44
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31562
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : internshipsystem- EPSS Score: %0.44
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31580
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : caretakerr-api- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31585
The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : home__internet- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2025-40628
SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update and delete databases via the “d” parameter in the “/article.php” endpoint.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection