Latest CVE Feed
-
9.8
CRITICALCVE-2024-3552
The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-B... Read more
Affected Products : web_directory_free- Published: Jun. 13, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2024-5898
A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file print_payroll.php. The manipulation of the argument id leads to sql injection. The attack ... Read more
- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37131
SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious actions on the applica... Read more
- Published: Jun. 13, 2024
- Modified: May. 20, 2025
-
9.8
CRITICALCVE-2024-37635
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg... Read more
- Published: Jun. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3912
Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.... Read more
Affected Products :- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37637
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.... Read more
- Published: Jun. 14, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-5671
Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager.... Read more
Affected Products : intrusion_prevention_system_manager- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37831
Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.... Read more
- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5871
The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthe... Read more
- Published: Jun. 15, 2024
- Modified: Feb. 07, 2025
-
9.8
CRITICALCVE-2024-4258
The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.13 via the settings parameter. This makes it possible for unauthenticated attackers to inc... Read more
Affected Products : video_gallery- Published: Jun. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6007
A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /protocol/iscgwtunnel/deleteiscgwrouteconf.php. The manipulation of the argument messagecontent leads to s... Read more
- Published: Jun. 15, 2024
- Modified: Feb. 05, 2025
-
9.8
CRITICALCVE-2024-38462
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.... Read more
Affected Products : irods- Published: Jun. 16, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-38466
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.... Read more
Affected Products : synthesis_image_system- Published: Jun. 16, 2024
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2024-36575
A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.... Read more
Affected Products :- Published: Jun. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6066
A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file payment_report.php. The manipulation of the argument month_of leads to sql injection. It is possib... Read more
Affected Products : best_house_rental_management_system- Published: Jun. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6083
A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp3.php of the component Media Upload Page. The manipulation of the argument file leads to unrestricted uplo... Read more
Affected Products : phpvibe- Published: Jun. 18, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6014
A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unknown function of the file edithis.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack ... Read more
Affected Products : document_management_system_project_in_php_with_source_code document_management_system- Published: Jun. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6110
A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file controller.php. The manipulation of the argument image lea... Read more
Affected Products : magbanua_beach_resort_online_reservation_system- Published: Jun. 18, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-6111
A vulnerability classified as critical has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument email leads to sql injection. It is possible to init... Read more
Affected Products : pool_of_bethesda_online_reservation_system- Published: Jun. 18, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-36116
Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite provides support for JavaDocs files, which are archives that contain documentation for artifacts. Specifically, JavadocEndp... Read more
- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024