Latest CVE Feed
-
9.8
CRITICALCVE-2023-2852
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron allows SQL Injection.This issue affects SelfPatron : before 2.0. ... Read more
Affected Products : selfpatron- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23753
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.... Read more
Affected Products : visforms- Published: Apr. 23, 2023
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2018-12491
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.... Read more
Affected Products : phpok- Published: Jun. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29798
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end d... Read more
- Published: Oct. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18527
OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter.... Read more
Affected Products : ownticket- Published: Oct. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9757
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.... Read more
Affected Products : craft_cms- Published: Mar. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13452
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.... Read more
Affected Products : gotenberg- Published: Jan. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-0912
EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 allows remote authenticated users to bypass intended password-change restrictions by leveraging access to (1) a different account with the same role as a target account or (2) an account's session at an un... Read more
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2024-6213
A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file login.php of the component Login Panel. The manipulation of the argument username leads to ... Read more
- Published: Jun. 21, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4831
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncode Ncep allows SQL Injection.This issue affects Ncep: before 20230914 . ... Read more
Affected Products : ncode_ncep- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37743
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.... Read more
Affected Products : knowledgegpt- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8950
A vulnerability was identified in Campcodes Online Recruitment Management System 1.0. This issue affects some unknown processing of the file /Recruitment/index.php?page=view_vacancy. The manipulation of the argument ID leads to sql injection. The attack m... Read more
Affected Products : online_recruitment_management_system- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2016-8596
Buffer overflow in the csp_can_process_frame in csp_if_can.c in the libcsp library v1.4 and earlier allows hostile components connected to the canbus to execute arbitrary code via a long csp packet.... Read more
- Published: Oct. 28, 2016
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-50706
An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function... Read more
Affected Products : thinkphp- Published: Aug. 05, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2016-8597
Buffer overflow in the csp_sfp_recv_fp in csp_sfp.c in the libcsp library v1.4 and earlier allows hostile components with network access to the SFP underlying network layers to execute arbitrary code via specially crafted SFP packets.... Read more
- Published: Oct. 28, 2016
- Modified: Aug. 14, 2025
-
9.8
CRITICALCVE-2025-6810
Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction with this l... Read more
Affected Products : activereports.net- Published: Jul. 07, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8047
The disable-right-click-powered-by-pixterme through v1.2 and pixter-image-digital-license thtough v1.0 WordPress plugins load a JavaScript file which has been compromised from an apparent abandoned S3 bucket. It can be used as a backdoor by those who cont... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Supply Chain
-
9.8
CRITICALCVE-2025-8951
A vulnerability has been found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of the file /admin/search.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remo... Read more
Affected Products : teachers_record_management_system- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8923
A vulnerability was determined in code-projects Job Diary 1.0. This vulnerability affects unknown code of the file /edit-details.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been di... Read more
Affected Products : job_diary- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-47539
Incorrect Privilege Assignment vulnerability in Themewinter Eventin allows Privilege Escalation. This issue affects Eventin: from n/a through 4.0.26.... Read more
Affected Products : eventin- Published: May. 23, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Authorization