Latest CVE Feed
-
9.8
CRITICALCVE-2018-16283
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.... Read more
Affected Products : wechat_brodcast- Published: Sep. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38375
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.... Read more
- Published: Feb. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0562
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to... Read more
Affected Products : bank_locker_management_system- Published: Jan. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33226
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input... Read more
Affected Products : salt- Published: Feb. 17, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2021-26277
The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.... Read more
- Published: Feb. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40021
QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.... Read more
- Published: Feb. 17, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2018-8856
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software contains hard-coded cryptographic key, which it uses for encryption of internal data.... Read more
Affected Products : e-alert_firmware- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0910
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_prod.php of the component GET Parameter Handler. The manipulation of the argument ID lea... Read more
- Published: Feb. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0917
A vulnerability, which was classified as critical, was found in SourceCodester Simple Customer Relationship Management System 1.0. This affects an unknown part of the file /php-scrm/login.php. The manipulation of the argument Password leads to sql injecti... Read more
- Published: Feb. 19, 2023
- Modified: Jun. 27, 2025
-
9.8
CRITICALCVE-2022-48329
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.... Read more
Affected Products : misp- Published: Feb. 20, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-26093
Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.... Read more
Affected Products : liima- Published: Feb. 20, 2023
- Modified: Mar. 17, 2025
-
9.8
CRITICALCVE-2018-17410
Horus CMS allows SQL Injection, as demonstrated by a request to the /busca or /home URI.... Read more
Affected Products : horus_cms- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17566
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.... Read more
Affected Products : thinkphp- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.... Read more
Affected Products : reverse_auction_factory- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17385
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.... Read more
Affected Products : social_factory- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-46637
Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.... Read more
- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2023-25158
GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filter expression language parsing, encoding and execution against a range of datastore. SQL Injection Vulnerabilities have been found when ... Read more
Affected Products : geotools- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24320
An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.... Read more
Affected Products : axcora- Published: Feb. 21, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-24080
A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.... Read more
Affected Products : myq- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2023-24108
MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.... Read more
Affected Products : mvctools- Published: Feb. 22, 2023
- Modified: Mar. 13, 2025