Latest CVE Feed
-
9.8
CRITICALCVE-2023-30354
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.... Read more
- Published: May. 10, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2021-21502
Dell PowerScale OneFS versions 8.1.0 – 9.1.0 contain a "use of SSH key past account expiration" vulnerability. A user on the network with the ISI_PRIV_AUTH_SSH RBAC privilege that has an expired account may potentially exploit this vulnerability, giving t... Read more
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29842
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devices... Read more
Affected Products : my_cloud_os_5 my_cloud_os my_cloud my_cloud_dl2100 my_cloud_dl4100 my_cloud_ex2_ultra my_cloud_ex2100 my_cloud_ex4100 my_cloud_mirror_g2 my_cloud_pr2100 +2 more products- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29841
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command co... Read more
Affected Products : my_cloud_os_5 my_cloud_os my_cloud my_cloud_dl2100 my_cloud_dl4100 my_cloud_ex2_ultra my_cloud_ex2100 my_cloud_ex4100 my_cloud_mirror_g2 my_cloud_pr2100 +2 more products- Published: May. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2643
A vulnerability classified as critical was found in SourceCodester File Tracker Manager System 1.0. This vulnerability affects unknown code of the file register/update_password.php of the component POST Parameter Handler. The manipulation of the argument ... Read more
Affected Products : file_tracker_manager_system- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31498
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.... Read more
- Published: May. 11, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2023-0855
Buffer overflow in IPP number-up attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:... Read more
Affected Products : mf1127c_firmware mf641cw_firmware mf642cdw_firmware mf644cdw_firmware mf741cdw_firmware mf743cdw_firmware mf745cdw_firmware mf746cdw_firmware lbp1127c_firmware lbp622cdw_firmware +80 more products- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0856
Buffer overflow in IPP sides attribute process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *:Sate... Read more
Affected Products : mf1127c_firmware mf641cw_firmware mf642cdw_firmware mf644cdw_firmware mf741cdw_firmware mf743cdw_firmware mf745cdw_firmware mf746cdw_firmware lbp1127c_firmware lbp622cdw_firmware +80 more products- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47129
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.... Read more
Affected Products : phpok- Published: May. 11, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2023-2661
A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Master.php. The manipulation of the argument id leads to sql injection. The attack... Read more
Affected Products : online_computer_and_laptop_store- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15963
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.... Read more
Affected Products : gigs_script- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15968
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.... Read more
Affected Products : mybuildersite- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15971
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.... Read more
Affected Products : same_date_pro- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-30330
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defaultframe/2.0/defaultframe_filter.php.... Read more
Affected Products : excellence_suite- Published: May. 12, 2023
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2023-27238
LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning.... Read more
Affected Products : lavalite- Published: May. 12, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2023-2694
A vulnerability was found in SourceCodester Online Exam System 1.0. It has been classified as critical. This affects an unknown part of the file /dosen/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data] leads t... Read more
- Published: May. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2695
A vulnerability was found in SourceCodester Online Exam System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /kelas/data of the component POST Parameter Handler. The manipulation of the argument columns[1][data... Read more
- Published: May. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15977
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.... Read more
Affected Products : expiring_download_links- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15979
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.... Read more
Affected Products : shareet- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15980
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.... Read more
Affected Products : us_zip_codes_database_script- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025