Latest CVE Feed
-
9.9
CRITICALCVE-2022-26075
An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests ... Read more
- EPSS Score: %9.34
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-8767
Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 619, Acronis Backup extension for Plesk (Linux) before build 555, Acronis... Read more
Affected Products :- Published: Sep. 17, 2024
- Modified: Sep. 20, 2024
-
9.9
CRITICALCVE-2023-3342
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible f... Read more
Affected Products : user_registration- EPSS Score: %3.34
- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-29214
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper e... Read more
Affected Products : xwiki- EPSS Score: %7.12
- Published: Apr. 16, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-8621
The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of ... Read more
Affected Products : daily_prayer_time- Published: Sep. 25, 2024
- Modified: Oct. 02, 2024
-
9.9
CRITICALCVE-2024-36393
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')... Read more
Affected Products : sysaid- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-41799
tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege could potentially set malicious .dme files existing on the host machine to be compiled and executed. These .d... Read more
Affected Products : tgstation-server- Published: Jul. 29, 2024
- Modified: Aug. 19, 2025
-
9.9
CRITICALCVE-2018-3832
An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows for uploading arbitrary MPFS binaries that could be modified to enable access to hidden resources which allow for uploading unsigned f... Read more
- EPSS Score: %0.42
- Published: Aug. 23, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2018-3897
An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON pa... Read more
- EPSS Score: %0.22
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2025-47663
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This issue affects Hospital Management System: from 47.0(20 through 11.... Read more
Affected Products : hospital_management_system- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2022-45808
SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.... Read more
Affected Products : learnpress- EPSS Score: %74.70
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2025-22133
WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads without proper validation, allowing the u... Read more
Affected Products : wegia- Published: Jan. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2023-36355
TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.... Read more
- EPSS Score: %38.26
- Published: Jun. 22, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-37462
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or ... Read more
Affected Products : xwiki- EPSS Score: %91.45
- Published: Jul. 14, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-38369
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of a document included using `{{include reference="targetdocument"/}}` is executed with the right of the includer and not with the right o... Read more
Affected Products : xwiki- Published: Jun. 24, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-4159
Unrestricted Upload of File with Dangerous Type in GitHub repository omeka/omeka-s prior to 4.0.3.... Read more
Affected Products : omeka_s- EPSS Score: %0.10
- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-38049
A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipulation.... Read more
Affected Products : easyappointments- Published: Jul. 09, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-44761
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.... Read more
Affected Products : eq_enterprise_management_system- Published: Aug. 28, 2024
- Modified: Nov. 18, 2024
-
9.9
CRITICALCVE-2024-48027
Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing allows Upload a Web Shell to a Web Server.This issue affects External featured image from bing: from n/a through 1.0.2.... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 16, 2024
-
9.9
CRITICALCVE-2022-24900
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When th... Read more
Affected Products : piano_led_visualizer- EPSS Score: %82.86
- Published: Apr. 29, 2022
- Modified: Nov. 21, 2024