Latest CVE Feed
-
9.9
CRITICALCVE-2024-54370
Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member allows Upload a Web Shell to a Web Server.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through 1.1.0.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.9
CRITICALCVE-2022-36084
cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`, users of that ... Read more
Affected Products : cruddl- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-36100
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document `Main... Read more
Affected Products : xwiki- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-2884
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint... Read more
Affected Products : gitlab- Published: Oct. 17, 2022
- Modified: May. 14, 2025
-
9.9
CRITICALCVE-2022-29176
Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so. To be vuln... Read more
Affected Products : rubygems.org- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-26510
A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerabili... Read more
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-26518
An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests t... Read more
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-26075
An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests ... Read more
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-25759
The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.... Read more
Affected Products : convert-svg-core- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-24768
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-l... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-23603
iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f43aa user input is not properly sanitized and code injection is possible. Users are advised to upgrade as soon as is possible. There ar... Read more
Affected Products : itunesrpc-remastered- Published: Feb. 01, 2022
- Modified: May. 05, 2025
-
9.9
CRITICALCVE-2023-22731
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows a template to c... Read more
Affected Products : shopware- Published: Jan. 17, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-21809
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.... Read more
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-20777
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host t... Read more
Affected Products : enterprise_nfv_infrastructure_software- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-1810
Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.... Read more
Affected Products : publify- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-1680
An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCI... Read more
Affected Products : gitlab- Published: Jun. 06, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-0767
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.... Read more
- Published: Mar. 07, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-0415
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.... Read more
Affected Products : gogs- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-43802
Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the attacker to gain admin privileges for the Etherpad instance. This, in turn, can be used to install a... Read more
Affected Products : etherpad- Published: Dec. 09, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-43362
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allows SQL Injection.This issue affects HBYS: from unspecified before 1.1. ... Read more
Affected Products : hbys- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024