Latest CVE Feed
-
9.8
CRITICALCVE-2008-10004
A vulnerability was found in Email Registration 5.x-2.1 on Drupal. It has been declared as critical. This vulnerability affects the function email_registration_user of the file email_registration.module. The manipulation of the argument namenew leads to s... Read more
Affected Products : email_registration- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3760
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med.This issue affects Mia-Med: before 1.0.0.58. ... Read more
Affected Products : mia-med- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26110
All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation. ... Read more
Affected Products : node-bluetooth- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1294
A vulnerability was found in SourceCodester File Tracker Manager System 1.0. It has been classified as critical. Affected is an unknown function of the file /file_manager/login.php of the component POST Parameter Handler. The manipulation of the argument ... Read more
- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1301
A vulnerability, which was classified as critical, has been found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this issue is some unknown functionality of the file deleteorder.php of the component GET Parameter Hand... Read more
Affected Products : friendly_island_pizza_website_and_ordering_system- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1310
A vulnerability, which was classified as critical, has been found in SourceCodester Online Graduate Tracer System 1.0. Affected by this issue is some unknown functionality of the file admin/prof.php. The manipulation of the argument id leads to sql inject... Read more
Affected Products : online_graduate_tracer_system online_graduate_tracer_system online_graduate_tracer_system- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24774
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.... Read more
Affected Products : funadmin- Published: Mar. 10, 2023
- Modified: Feb. 28, 2025
-
9.8
CRITICALCVE-2023-27852
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.... Read more
- Published: Mar. 10, 2023
- Modified: Feb. 27, 2025
-
9.8
CRITICALCVE-2022-48367
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.... Read more
Affected Products : ez_platform_kernel digital_experience_platform kernel ezplatform-http-cache-fastly fastly- Published: Mar. 12, 2023
- Modified: Mar. 04, 2025
-
9.8
CRITICALCVE-2023-27061
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a ... Read more
- Published: Mar. 13, 2023
- Modified: Feb. 27, 2025
-
9.8
CRITICALCVE-2023-1198
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection.This issue affects Starcities: through 1.3. ... Read more
Affected Products : starcities- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25207
PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.... Read more
Affected Products : dpd_france- Published: Mar. 13, 2023
- Modified: Mar. 03, 2025
-
9.8
CRITICALCVE-2022-39216
Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset password token is generated without any randomness parameter. This may lead to account takeover. The issue is fixed in versions 2.7.8 ... Read more
Affected Products : itop- Published: Mar. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-14403
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.... Read more
Affected Products : eyesofnetwork- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-27240
Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.... Read more
- Published: Mar. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1461
A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been declared as critical. This vulnerability affects the function query of the file createCategories.php. The manipulation of the argument categoriesStatus leads to sql inj... Read more
Affected Products : canteen_management_system- Published: Mar. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1468
A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/?page=reports&date_from=2023-02-17&date_to=2023-03-17 of the c... Read more
- Published: Mar. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28116
Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write can occur in the BLE L2CAP module of the Contiki-NG operating system. The network stack of Contiki-NG us... Read more
Affected Products : contiki-ng- Published: Mar. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26805
Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.... Read more
- Published: Mar. 19, 2023
- Modified: Feb. 27, 2025
-
9.8
CRITICALCVE-2023-26806
Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,... Read more
- Published: Mar. 19, 2023
- Modified: Feb. 27, 2025