Latest CVE Feed
-
9.8
CRITICALCVE-2024-25214
An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.... Read more
Affected Products : employee_management_system- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25215
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.... Read more
Affected Products : employee_management_system- Published: Feb. 14, 2024
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2024-25216
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.... Read more
Affected Products : employee_management_system- Published: Feb. 14, 2024
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2024-24300
4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.... Read more
- Published: Feb. 14, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2024-26260
The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on th... Read more
- Published: Feb. 15, 2024
- Modified: Jan. 23, 2025
-
9.8
CRITICALCVE-2024-22426
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get e... Read more
Affected Products : recoverpoint_for_virtual_machines- Published: Feb. 16, 2024
- Modified: Jan. 23, 2025
-
9.8
CRITICALCVE-2022-42443
An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploading of files. IBM X-Force ID: 238535.... Read more
- Published: Feb. 17, 2024
- Modified: Jan. 22, 2025
-
9.8
CRITICALCVE-2023-6749
Unchecked length coming from user input in settings shell... Read more
Affected Products : zephyr- Published: Feb. 18, 2024
- Modified: Jan. 22, 2025
-
9.8
CRITICALCVE-2024-24793
A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that is used later. To trigger this vulnerability, an attacker w... Read more
Affected Products : libdicom- Published: Feb. 20, 2024
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2023-51828
A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter in get_next_notice function.... Read more
- Published: Feb. 21, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2024-1702
A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /edit.php. The manipulation leads to sql injection. The attack may be launched remotely. T... Read more
Affected Products : php_mysql_user_signup_login_system- Published: Feb. 21, 2024
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2024-1831
A vulnerability, which was classified as critical, was found in SourceCodester Complete File Management System 1.0. Affected is an unknown function of the file users/index.php of the component Login Form. The manipulation of the argument username with the... Read more
Affected Products : complete_file_management_system- Published: Feb. 23, 2024
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2023-51518
Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leveraged as part of an exploit chain that could result in pri... Read more
Affected Products : james- Published: Feb. 27, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-1926
A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /app/ajax/search_sales_report.php. The manipulation of the argument cus... Read more
Affected Products : free_and_open_source_inventory_management_system- Published: Feb. 27, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-25169
An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.... Read more
Affected Products : mezzanine- Published: Feb. 28, 2024
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2023-48245
The vulnerability allows an unauthenticated remote attacker to upload arbitrary files under the context of the application OS user (“root”) via a crafted HTTP request.... Read more
Affected Products : nexo-os nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\) nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\) nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\) nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\) nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\) nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\) nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\) nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\) nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\) +11 more products- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1927
A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /Admin/login.php. The manipulation of the argument txtpassword leads to sql i... Read more
- Published: Feb. 29, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-25180
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after in... Read more
Affected Products : pdfmake- Published: Feb. 29, 2024
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2024-2147
A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/login.php. The manipulation of the argument username leads to sql inject... Read more
Affected Products : online_mobile_store_management_system- Published: Mar. 03, 2024
- Modified: Jan. 02, 2025
-
9.8
CRITICALCVE-2024-2154
A vulnerability has been found in SourceCodester Online Mobile Management Store 1.0 and classified as critical. This vulnerability affects unknown code of the file view_product.php. The manipulation of the argument id leads to sql injection. The attack ca... Read more
Affected Products : online_mobile_store_management_system- Published: Mar. 04, 2024
- Modified: Dec. 20, 2024