Latest CVE Feed
-
9.8
CRITICALCVE-2023-36670
A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as root by sending crafted TCP requests to the device.... Read more
- Published: Jul. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-14094
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system.... Read more
Affected Products : smart_protection_server- Published: Jan. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3679
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=save_inquiry of the component HTTP POST Request Handle... Read more
Affected Products : lost_and_found_information_system- Published: Jul. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3811
A vulnerability was found in Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file patientprofile.php. The manipulation of the argument address leads to sql injection. The attack may be initi... Read more
Affected Products : hospital_management_system- Published: Jul. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16608
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within exec.jsp. The issue results from ... Read more
Affected Products : enterprise_manager- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16610
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within upload_save_do.jsp. The issue res... Read more
Affected Products : enterprise_manager- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3836
A vulnerability classified as critical was found in Dahua Smart Park Management up to 20230713. This vulnerability affects unknown code of the file /emap/devicePoint_addImgIco?hasSubsystem=true. The manipulation of the argument upload leads to unrestricte... Read more
Affected Products : smart_parking_management- Published: Jul. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5972
SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.... Read more
Affected Products : quickad- Published: Jan. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5979
SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.... Read more
Affected Products : wchat- Published: Jan. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-46898
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a Z... Read more
- Published: Jul. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37258
DataEase is an open source data visualization analysis tool. Prior to version 1.18.9, DataEase has a SQL injection vulnerability that can bypass blacklists. The vulnerability has been fixed in v1.18.9. There are no known workarounds.... Read more
Affected Products : dataease- Published: Jul. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26859
SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.... Read more
Affected Products : brevo- Published: Jul. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33744
TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.... Read more
- Published: Jul. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3987
A vulnerability was found in SourceCodester Simple Online Mens Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=user/manage_user&id=3. The manipulation of the argument id leads to sq... Read more
- Published: Jul. 28, 2023
- Modified: Feb. 11, 2025
-
9.8
CRITICALCVE-2023-3988
A vulnerability was found in Cafe Billing System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file index.php of the component Order Handler. The manipulation of the argument id leads to sql injec... Read more
Affected Products : cafe_billing_system- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38992
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.... Read more
Affected Products : jeecg_boot- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39023
university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument.... Read more
Affected Products : university_compass- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17976
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.... Read more
Affected Products : perfex_crm- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32225
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method. ... Read more
- Published: Jul. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Jul. 30, 2023
- Modified: Nov. 21, 2024