Latest CVE Feed
-
9.8
CRITICALCVE-2024-7363
A vulnerability, which was classified as critical, was found in SourceCodester Tracking Monitoring Management System 1.0. Affected is an unknown function of the file /manage_person.php. The manipulation of the argument id leads to sql injection. It is pos... Read more
Affected Products : tracking_monitoring_management_system- Published: Aug. 01, 2024
- Modified: Aug. 09, 2024
-
9.8
CRITICALCVE-2024-7365
A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_establishment.php. The manipulation of the argument id leads to sql ... Read more
Affected Products : tracking_monitoring_management_system- Published: Aug. 01, 2024
- Modified: Aug. 09, 2024
-
9.8
CRITICALCVE-2024-7369
A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads t... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 01, 2024
- Modified: Aug. 07, 2024
-
9.8
CRITICALCVE-2024-7377
A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_result.php. The manipulation of the argument qid leads to sql injecti... Read more
Affected Products : simple_realtime_quiz_system- Published: Aug. 02, 2024
- Modified: Aug. 09, 2024
-
9.8
CRITICALCVE-2024-7366
A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?action=login of the component Login. The manipulation of the argument username le... Read more
Affected Products : tracking_monitoring_management_system- Published: Aug. 01, 2024
- Modified: Aug. 09, 2024
-
9.8
CRITICALCVE-2024-38882
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in a... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-38886
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.... Read more
Affected Products : caterease- Published: Aug. 02, 2024
- Modified: Sep. 10, 2024
-
9.8
CRITICALCVE-2024-7439
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buf... Read more
- Published: Aug. 03, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2024-7449
A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument email leads to sql injection. It is possible to launch th... Read more
Affected Products : placement_management_system- Published: Aug. 04, 2024
- Modified: Aug. 20, 2024
-
9.8
CRITICALCVE-2024-7452
A vulnerability was found in itsourcecode Placement Management System 1.0. It has been classified as critical. This affects an unknown part of the file view_company.php. The manipulation of the argument id leads to sql injection. It is possible to initiat... Read more
Affected Products : placement_management_system- Published: Aug. 04, 2024
- Modified: Aug. 09, 2024
-
9.8
CRITICALCVE-2024-7458
A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of the component Database Management/Deployment Management. The manipulation o... Read more
Affected Products : eladmin- Published: Aug. 04, 2024
- Modified: Aug. 06, 2024
-
9.8
CRITICALCVE-2024-7465
A vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747_B20191224. Affected is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument http_host leads to buffer overflow. It is possible ... Read more
- Published: Aug. 05, 2024
- Modified: Aug. 15, 2024
-
9.8
CRITICALCVE-2024-7495
A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The manipulation of the argument image leads to unrestricted uplo... Read more
Affected Products : laravel_accounting_system- Published: Aug. 06, 2024
- Modified: Aug. 19, 2024
-
9.8
CRITICALCVE-2024-5828
Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.... Read more
- Published: Aug. 06, 2024
- Modified: Jan. 08, 2025
-
9.8
CRITICALCVE-2024-33968
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2024-33970
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the foll... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 08, 2024
-
9.8
CRITICALCVE-2024-39228
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a shell inject... Read more
Affected Products : mt6000_firmware mt6000 a1300_firmware a1300 x300b_firmware x300b ax1800_firmware ax1800 axt1800_firmware axt1800 +46 more products- Published: Aug. 06, 2024
- Modified: Aug. 15, 2024
-
9.8
CRITICALCVE-2024-42395
There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system l... Read more
- Published: Aug. 06, 2024
- Modified: Aug. 12, 2024
-
9.8
CRITICALCVE-2024-7578
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the file /var/www/cmd.php. The manipulation of the argument cmd leads to improper authorization. It is possibl... Read more
- Published: Aug. 07, 2024
- Modified: Aug. 28, 2024
-
9.8
CRITICALCVE-2024-7584
A vulnerability, which was classified as critical, was found in Tenda i22 1.0.0.3(4687). Affected is the function formApPortalPhoneAuth of the file /goform/apPortalPhoneAuth. The manipulation of the argument data leads to buffer overflow. It is possible t... Read more
- Published: Aug. 07, 2024
- Modified: Sep. 11, 2024