Latest CVE Feed
-
9.8
CRITICALCVE-2024-55515
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.... Read more
Affected Products : msg2300_firmware msg2300 msg2100e_firmware msg2100e msg2200_firmware msg2200 msg1200_firmware msg1200- Published: Dec. 17, 2024
- Modified: Apr. 28, 2025
-
9.8
CRITICALCVE-2024-12287
The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.2. This is due to the plugin not properly verifying a user's identity prior to authenticating them. This makes it possible for u... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-4996
Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Wapro ERP installations. This issue affec... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-56059
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mighty Digital Partners allows Object Injection.This issue affects Partners: from n/a through 0.2.0.... Read more
Affected Products :- Published: Dec. 18, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2023-34990
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.... Read more
Affected Products : fortiwlm- Published: Dec. 18, 2024
- Modified: Jun. 05, 2025
-
9.8
CRITICALCVE-2021-27228
An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are held in an internal JS Object. Therefore an attacker can use JS Proto Method names (such as constructor or hasOwnProperty) to convince... Read more
Affected Products : shinobi_pro- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-28429
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})... Read more
Affected Products : geojson2kml- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32589
A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and F... Read more
- Published: Dec. 19, 2024
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2021-26102
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configur... Read more
Affected Products : fortiwan- Published: Dec. 19, 2024
- Modified: Jan. 21, 2025
-
9.8
CRITICALCVE-2024-12787
A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/check_student_login.php. The manipulation of the argument... Read more
Affected Products : attendance_tracking_management_system- Published: Dec. 19, 2024
- Modified: Jan. 10, 2025
-
9.8
CRITICALCVE-2024-54983
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 31, 2024
-
9.8
CRITICALCVE-2024-12571
The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it possible for unauthenticated attackers to include and execute arbitr... Read more
Affected Products :- Published: Dec. 20, 2024
- Modified: Dec. 20, 2024
-
9.8
CRITICALCVE-2024-12884
A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be laun... Read more
Affected Products : e-commerce_site- Published: Dec. 21, 2024
- Modified: Jan. 10, 2025
-
9.8
CRITICALCVE-2024-12894
A vulnerability, which was classified as critical, was found in TreasureHuntGame TreasureHunt up to 963e0e0. Affected is an unknown function of the file TreasureHunt/acesso.php. The manipulation of the argument usuario leads to sql injection. It is possib... Read more
Affected Products : treasurehunt- Published: Dec. 22, 2024
- Modified: Jan. 10, 2025
-
9.8
CRITICALCVE-2024-12927
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected by this issue is some unknown functionality of the file /faculty/check_faculty_login.php. The manipulation of the argume... Read more
Affected Products : attendance_tracking_management_system- Published: Dec. 25, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-12945
A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /account.php. The manipulation of the argument email/pass leads to sql injection. The attack can be initiat... Read more
- Published: Dec. 26, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2021-26904
LMA ISIDA Retriever 5.2 allows SQL Injection.... Read more
Affected Products : retriever- Published: Feb. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-12956
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file /add_achievement_details.php. The manipulation of the argument ach_certy leads to unrestricte... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 26, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-12959
A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerability affects unknown code of the file /update_personal_details.php. The manipulation of the argument q leads to sql injection. The attack ... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 26, 2024
- Modified: Dec. 26, 2024
-
9.8
CRITICALCVE-2024-12961
A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the file /update_ach_details.php. The manipulation of the argument q leads to sql injection. It is possib... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 26, 2024
- Modified: Apr. 22, 2025