Latest CVE Feed
-
9.8
CRITICALCVE-2015-3252
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.... Read more
Affected Products : cloudstack- EPSS Score: %1.87
- Published: Feb. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2022-45982
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.... Read more
Affected Products : thinkphp- EPSS Score: %0.97
- Published: Feb. 08, 2023
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2024-53438
EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing ... Read more
Affected Products : churchcrm- Published: Nov. 22, 2024
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2025-27641
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-2024-009.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2023-24350
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.... Read more
- EPSS Score: %2.08
- Published: Feb. 10, 2023
- Modified: Mar. 24, 2025
-
9.8
CRITICALCVE-2022-34440
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to th... Read more
- EPSS Score: %0.13
- Published: Jan. 11, 2023
- Modified: May. 20, 2025
-
9.8
CRITICALCVE-2023-26323
A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.... Read more
Affected Products : app_market- Published: Aug. 28, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2024-8999
lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnerability allows any user to export the entire database data by creating a stream to Google BigQuery without ... Read more
Affected Products : lunary- Published: Mar. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-8502
A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the AgentServerServicer.create_agent method, whe... Read more
Affected Products : agentscope- Published: Mar. 20, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-31049
Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-48175
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.... Read more
Affected Products : rukovoditel- EPSS Score: %5.23
- Published: Jan. 30, 2023
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2024-31807
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.... Read more
- Published: Apr. 08, 2024
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2025-1307
The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the newscrunch_install_and_activate_plugin() function in all versions up to, and including, 1.8.4.1. This makes it possible for authenticated a... Read more
Affected Products : newscrunch- Published: Mar. 04, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2023-24762
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.... Read more
- EPSS Score: %1.70
- Published: Mar. 13, 2023
- Modified: Mar. 03, 2025
-
9.8
CRITICALCVE-2024-8262
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927.... Read more
Affected Products : student_affairs_information_system- Published: Mar. 03, 2025
- Modified: Mar. 10, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-25320
Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.... Read more
- Published: Feb. 16, 2024
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2024-33403
A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.... Read more
Affected Products : complete_web-based_school_management_system- Published: May. 06, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2024-38909
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.... Read more
Affected Products : elfinder- Published: Jul. 30, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2022-35620
D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.... Read more
- EPSS Score: %25.25
- Published: Aug. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2094
A vulnerability has been found in SourceCodester Vehicle Service Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/mechanics/manage_mechanic.php. The manipulation of the argument id leads to sql i... Read more
- EPSS Score: %0.05
- Published: Apr. 15, 2023
- Modified: Feb. 06, 2025