Latest CVE Feed
-
9.8
CRITICALCVE-2024-24579
stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths ... Read more
Affected Products : stereoscope- Published: Jan. 31, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0655
A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The manipulation of the argument sort leads to sql injection. The exploit ha... Read more
Affected Products : novel-plus- Published: Jan. 18, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1113
A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadUnity of the file /application/index/controller/Unity.php. The manipulation of the argument file leads to unrestricted upload. It is possib... Read more
Affected Products : openbi- Published: Jan. 31, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47072
SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..... Read more
Affected Products : enterprise_architect- Published: Jan. 31, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-0927
A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been classified as critical. Affected is the function fromAddressNat. The manipulation of the argument entrys/mitInterface/page leads to stack-based buffer overflow. It is possible t... Read more
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12976
In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.... Read more
Affected Products : go_doc_dot_org- Published: Jul. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32333
IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.... Read more
- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23978
Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected products are no longer supported.... Read more
- Published: Feb. 02, 2024
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2024-0487
A vulnerability was found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/action/delete-vaccine.php. The manipulation of the argument ref leads to sq... Read more
Affected Products : fighting_cock_information_system- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13448
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the country_id parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0496
A vulnerability was found in Kashipara Billing Software 1.0 and classified as critical. This issue affects some unknown processing of the file item_list_edit.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql ... Read more
Affected Products : billing_software- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0497
A vulnerability was found in Campcodes Student Information System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Users.php?f=save. The manipulation of the argument username leads to sql injection. It is possi... Read more
Affected Products : simple_student_information_system- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6989
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthent... Read more
Affected Products : shield_security- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0709
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio... Read more
Affected Products : cryptocurrency_widgets- Published: Feb. 05, 2024
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2024-0523
A vulnerability was found in CmsEasy up to 7.7.7. It has been declared as critical. Affected by this vulnerability is the function getslide_child_action in the library lib/admin/language_admin.php. The manipulation of the argument sid leads to sql injecti... Read more
Affected Products : cmseasy- Published: Jan. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23049
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.... Read more
Affected Products : symphony- Published: Feb. 05, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2023-6234
Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera... Read more
Affected Products : mf1238_ii_firmware mf1643i_ii_firmware mf1643if_ii_firmware mf451dw_firmware mf452dw_firmware mf453dw_firmware mf455dw_firmware lbp1238_ii_firmware lbp236dw_firmware lbp237dw_firmware +48 more products- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24592
Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and delete files. ... Read more
Affected Products : clearml- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24015
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit... Read more
Affected Products : novel-plus- Published: Feb. 06, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2024-1262
A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file /api/controllers/merchant/design/MaterialController.php of the component API. The manipulation of th... Read more
Affected Products : jpshop- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024