Latest CVE Feed
-
9.8
CRITICALCVE-2017-9819
The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication.... Read more
Affected Products : bharat_interface_for_money_\(bhim\)- EPSS Score: %0.55
- Published: Aug. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2000-1218
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to po... Read more
- EPSS Score: %2.22
- Published: Apr. 14, 2000
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2023-43453
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.... Read more
- EPSS Score: %3.93
- Published: Dec. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34388
An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication. See product Instruction Manual Appendix... Read more
- EPSS Score: %0.12
- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2002-1820
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a."... Read more
Affected Products : ultimate_php_board- EPSS Score: %1.53
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2004-0285
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.... Read more
- EPSS Score: %29.93
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2004-2214
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.... Read more
Affected Products : appweb_http_server- EPSS Score: %0.62
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2005-1141
Integer overflow in the readpgm function in pnm.c for GOCR 0.40, when using the netpbm library, allows remote attackers to execute arbitrary code via a PNM file with large width and height values, which leads to a heap-based buffer overflow.... Read more
Affected Products : optical_character_recognition- EPSS Score: %14.34
- Published: Apr. 15, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-6253
A vulnerability was found in itsourcecode Online Food Ordering System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /purchase.php. The manipulation of the argument customer leads to sql injection. The att... Read more
Affected Products : online_food_ordering_system- Published: Jun. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2363
A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. This issue affects some unknown processing of the file view_room.php. The manipulation of the argument id leads to sql injection. The attack... Read more
- EPSS Score: %0.05
- Published: Apr. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-3435
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.... Read more
Affected Products : newsworld- EPSS Score: %0.86
- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2006-3136
Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, ... Read more
Affected Products : nucleus_cms- EPSS Score: %2.75
- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2006-5021
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) ad... Read more
Affected Products : redblog- EPSS Score: %1.48
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2006-5603
SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party informa... Read more
Affected Products : snitz_forums_2000- EPSS Score: %0.36
- Published: Oct. 30, 2006
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2006-5610
PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : fully_modded_phpbb- EPSS Score: %1.04
- Published: Oct. 31, 2006
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2007-0681
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.... Read more
Affected Products : extcalendar- EPSS Score: %4.68
- Published: Feb. 03, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2006-7105
PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. NOTE: in the original disclosure, filename is used in a function definition, so th... Read more
Affected Products : smarty- EPSS Score: %1.12
- Published: Mar. 03, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2023-43548
Memory corruption while parsing qcp clip with invalid chunk data size.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6430_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware +305 more products- Published: Mar. 04, 2024
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2007-2422
Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE dis... Read more
Affected Products : modules_builder- EPSS Score: %0.77
- Published: May. 02, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2007-4043
file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a name parameter ending with a "%00.gif" sequence. NOTE: a separate traversal vulnerability could be leveraged ... Read more
Affected Products : securityreporter- EPSS Score: %0.34
- Published: Jul. 27, 2007
- Modified: Apr. 09, 2025