Latest CVE Feed
-
9.8
CRITICALCVE-2024-0992
A vulnerability was found in Tenda i6 1.0.0.9(3857) and classified as critical. This issue affects the function formwrlSSIDset of the file /goform/wifiSSIDset of the component httpd. The manipulation of the argument index leads to stack-based buffer overf... Read more
- Published: Jan. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0925
A vulnerability has been found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This vulnerability affects the function formSetVirtualSer. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be init... Read more
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24141
Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.... Read more
Affected Products : school_task_manager- Published: Jan. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1021
A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the function readRawText of the component HTTP Request Handler. The manipulation of the argument url leads to server-side request forgery. ... Read more
Affected Products : rebuild- Published: Jan. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1035
A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function uploadIcon of the file /application/index/controller/Icon.php. The manipulation of the argument image leads to unrestricted upload. Th... Read more
- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1036
A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon of the file /application/index/controller/Screen.php of the component Icon Handler. The manipulation leads to unrestricted upload. The a... Read more
Affected Products : openbi- Published: Jan. 30, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-24579
stereoscope is a go library for processing container images and simulating a squash filesystem. Prior to version 0.0.1, it is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths ... Read more
Affected Products : stereoscope- Published: Jan. 31, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0655
A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The manipulation of the argument sort leads to sql injection. The exploit ha... Read more
Affected Products : novel-plus- Published: Jan. 18, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1113
A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadUnity of the file /application/index/controller/Unity.php. The manipulation of the argument file leads to unrestricted upload. It is possib... Read more
Affected Products : openbi- Published: Jan. 31, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47072
SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..... Read more
Affected Products : enterprise_architect- Published: Jan. 31, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-0927
A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been classified as critical. Affected is the function fromAddressNat. The manipulation of the argument entrys/mitInterface/page leads to stack-based buffer overflow. It is possible t... Read more
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12976
In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.... Read more
Affected Products : go_doc_dot_org- Published: Jul. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32333
IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.... Read more
- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23978
Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected products are no longer supported.... Read more
- Published: Feb. 02, 2024
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2024-0487
A vulnerability was found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/action/delete-vaccine.php. The manipulation of the argument ref leads to sq... Read more
Affected Products : fighting_cock_information_system- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13448
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the country_id parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0496
A vulnerability was found in Kashipara Billing Software 1.0 and classified as critical. This issue affects some unknown processing of the file item_list_edit.php of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql ... Read more
Affected Products : billing_software- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0497
A vulnerability was found in Campcodes Student Information System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Users.php?f=save. The manipulation of the argument username leads to sql injection. It is possi... Read more
Affected Products : simple_student_information_system- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6989
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthent... Read more
Affected Products : shield_security- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0709
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparatio... Read more
Affected Products : cryptocurrency_widgets- Published: Feb. 05, 2024
- Modified: Mar. 18, 2025