Latest CVE Feed
-
9.8
CRITICALCVE-2020-21662
SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.... Read more
Affected Products : yunyecms- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34644
Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wire... Read more
Affected Products : rg-ew1200r_firmware rg-ew300_firmware rg-ew3200gx_firmware rg-ew1200g_firmware rg-ew1800gx_firmware rg-ew300r_firmware rg-ew1200_firmware rg-eg3000xe_firmware rg-eg105g_firmware rg-eg305gh-p-e_firmware +120 more products- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37771
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.... Read more
Affected Products : art_gallery_management_system- Published: Jul. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3850
A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_category of the component HTTP POST Requ... Read more
Affected Products : lost_and_found_information_system- Published: Jul. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26317
Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or... Read more
Affected Products : xiaomi_router_firmware- Published: Aug. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1437
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remot... Read more
Affected Products : webaccess\/scada- Published: Aug. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4121
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722. It has been classified as critical. Affected is an unknown function. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to launch the... Read more
- Published: Aug. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6576
SQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.... Read more
Affected Products : event_manager- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29689
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary cod... Read more
Affected Products : pyrocms- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33376
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.... Read more
Affected Products : connected_io- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33379
Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and se... Read more
- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5442
A Stack-based Buffer Overflow issue was discovered in Fuji Electric V-Server VPR 4.0.1.0 and prior. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.... Read more
- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39346
LinuxASMCallGraph is software for drawing the call graph of the programming code. Linux ASMCallGraph before commit 20dba06bd1a3cf260612d4f21547c25002121cd5 allows attackers to cause a remote code execution on the server side via uploading a crafted ZIP fi... Read more
Affected Products : linuxasmcallgraph- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4165
A vulnerability, which was classified as critical, was found in Tongda OA. This affects an unknown part of the file general/system/seal_manage/iweboffice/delete_seal.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has ... Read more
- Published: Aug. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32090
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials ... Read more
- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23757
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.... Read more
Affected Products : bestaddon_gallery- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34476
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.... Read more
Affected Products : proforms- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38932
Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter in the SafeEmailFilter function.... Read more
Affected Products : f1202_firmware fh1202_firmware pw201a_firmware pa202_firmware f1202 fh1202 pw201a pa202- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38936
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir par... Read more
Affected Products : ac6_firmware ac9_firmware ac10_firmware ac7_firmware ac1206_firmware ac5_firmware f1203_firmware fh1205_firmware fh1203_firmware ac6 +8 more products- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12465
Multiple integer overflows in CCN-lite before 2.00 allow context-dependent attackers to have unspecified impact via vectors involving the (1) vallen variable in the iottlv_parse_sequence function or (2) typ, vallen and i variables in the localrpc_parse fu... Read more
Affected Products : ccn-lite- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024