Latest CVE Feed
-
9.8
CRITICALCVE-2023-24108
MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.... Read more
Affected Products : mvctools- Published: Feb. 22, 2023
- Modified: Mar. 13, 2025
-
9.8
CRITICALCVE-2023-0960
A vulnerability was found in SeaCMS 11.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/config.ftp.php of the component Picture Management. The manipulation leads to deserialization. The attack may be... Read more
Affected Products : seacms- Published: Feb. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0963
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. ... Read more
- Published: Feb. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24812
Misskey is an open source, decentralized social media platform. In versions prior to 13.3.3 SQL injection is possible due to insufficient parameter validation in the note search API by tag (notes/search-by-tag). This has been fixed in version 13.3.3. User... Read more
Affected Products : misskey- Published: Feb. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0939
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection.This issue affects Online Services Software: before 1.17. ... Read more
Affected Products : online_services- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0986
A vulnerability classified as critical has been found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/?page=user/manage_user of the component Edit User. The manipulation of the argument id leads to sql... Read more
Affected Products : sales_tracker_management_system- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24104
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.... Read more
- Published: Feb. 23, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-24212
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.... Read more
- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-9079
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handler... Read more
Affected Products : lenovoemc_firmware storcenter_px12-450r_firmware storcenter_px12-400r_firmware storcenter_px4-300r_firmware storcenter_px6-300d_firmware storcenter_px4-300d_firmware storcenter_px2-300d_firmware storcenter_ix4-300d_firmware storcenter_ix2_firmware storcenter_ix2-dl_firmware +31 more products- Published: Sep. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33224
File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.... Read more
Affected Products : umbraco_forms- Published: Feb. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-35370
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.... Read more
Affected Products : imcat- Published: Feb. 24, 2023
- Modified: Mar. 12, 2025
-
9.8
CRITICALCVE-2023-24189
An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.... Read more
Affected Products : urule- Published: Feb. 24, 2023
- Modified: Mar. 12, 2025
-
9.8
CRITICALCVE-2022-48259
There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges.... Read more
- Published: Feb. 27, 2023
- Modified: Mar. 11, 2025
-
9.8
CRITICALCVE-2018-17786
On D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require authentication, which allows remote attackers to execute arbitrary code.... Read more
- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-22748
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploita... Read more
- Published: Mar. 01, 2023
- Modified: Mar. 07, 2025
-
9.8
CRITICALCVE-2023-22750
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploita... Read more
- Published: Mar. 01, 2023
- Modified: Mar. 07, 2025
-
9.8
CRITICALCVE-2018-17881
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.... Read more
- Published: Oct. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1114
Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation.This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.100. ... Read more
Affected Products : e-belediye- Published: Mar. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37937
Pre-auth memory corruption in HPE Serviceguard... Read more
Affected Products : serviceguard_for_linux- Published: Mar. 01, 2023
- Modified: Mar. 17, 2025
-
9.8
CRITICALCVE-2021-4328
A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function goods_detail of the file ApiController.class.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launc... Read more
Affected Products : lionfish_cms- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024