Latest CVE Feed
-
9.8
CRITICALCVE-2023-49959
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST reques... Read more
Affected Products : profinet-inspektor_nt- Published: Feb. 26, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-6677
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection.This issue affects Online Collection: before v.1.0.2. ... Read more
Affected Products : online_collection- EPSS Score: %0.07
- Published: Feb. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19740
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.... Read more
Affected Products : oempro- EPSS Score: %0.91
- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12585
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.... Read more
- EPSS Score: %11.68
- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19840
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.... Read more
Affected Products : zonedirector_1200_firmware unleashed r310 zonedirector_1200 h320 h510 r710 r720 t610 r510 +7 more products- EPSS Score: %21.70
- Published: Jan. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43457
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.... Read more
Affected Products : service_provider_management_system- EPSS Score: %1.26
- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31719
FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.... Read more
Affected Products : fuxa- EPSS Score: %59.89
- Published: Sep. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40922
kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent().... Read more
Affected Products : kerawen- EPSS Score: %0.07
- Published: Nov. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23638
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo ... Read more
Affected Products : dubbo- EPSS Score: %67.11
- Published: Mar. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41418
AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.... Read more
Affected Products : ariang- EPSS Score: %0.30
- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37800
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function fromSetRouteStatic.... Read more
- EPSS Score: %0.44
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11082
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to log... Read more
- EPSS Score: %0.29
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10625
WebAccess/NMS (versions prior to 3.0.2) allows an unauthenticated remote user to create a new admin account.... Read more
Affected Products : webaccess\/nms- EPSS Score: %0.25
- Published: Apr. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18693
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. There is a buffer overflow in the fps sysfs entry. The Samsung ID is SVE-2016-7510 (January 2017).... Read more
Affected Products : android- EPSS Score: %0.16
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0391
The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.... Read more
- EPSS Score: %0.86
- Published: Jul. 02, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2018-18242
youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86.... Read more
Affected Products : youke_365- EPSS Score: %0.26
- Published: Oct. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24167
Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.... Read more
- EPSS Score: %4.33
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0682
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to read/send mail or change the configuration via unspecified vectors.... Read more
- EPSS Score: %1.09
- Published: Nov. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0779
The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.... Read more
Affected Products : tomee- EPSS Score: %9.01
- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-21833
An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger... Read more
Affected Products : imagegear- EPSS Score: %0.43
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024