Latest CVE Feed
-
9.8
CRITICALCVE-2024-4320
A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due to improper handling... Read more
- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25435
Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using recovery partition in wireless firmware download mode.... Read more
Affected Products : tizen- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23580
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.... Read more
Affected Products : pbootcms- Published: Jul. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4146
In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they should not have access to. Specifically, the vulnerability is located in the ... Read more
Affected Products : lunary- Published: Jun. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-30529
Missing Authorization vulnerability in Tainacan.Org Tainacan.This issue affects Tainacan: from n/a through 0.20.7.... Read more
Affected Products : tainacan- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31273
Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.3.... Read more
Affected Products : js_help_desk- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-33545
Missing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10.... Read more
Affected Products : wzone- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45188
IBM Engineering Lifecycle Optimization Publishing 7.0.2 and 7.03 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions. By sending a specially crafted request, a remote attacker could exploit this v... Read more
Affected Products : engineering_lifecycle_optimization_-_publishing- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31275
Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4.... Read more
Affected Products : eventprime- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31283
Missing Authorization vulnerability in zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.6.2.... Read more
Affected Products : advanced_local_pickup_for_woocommerce- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-35307
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.... Read more
- Published: Jun. 10, 2024
- Modified: Sep. 16, 2025
-
9.8
CRITICALCVE-2024-3700
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software i... Read more
Affected Products : simple_care- Published: Jun. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23390
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.... Read more
Affected Products : total4- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37014
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.... Read more
Affected Products : langflow- Published: Jun. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37393
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltrate data from Active Directory through blind LDAP injection attacks against ... Read more
Affected Products : multi-factor_authentication_solutions- Published: Jun. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-36360
OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthenticated attacker sends a specially crafted HTTP request, an arbitrary OS command may be executed with the p... Read more
Affected Products :- Published: Jun. 11, 2024
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2024-2011
A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policy... Read more
- Published: Jun. 11, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34690
iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980.... Read more
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1577
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP software versions th... Read more
Affected Products : megabip- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-37036
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.... Read more
Affected Products : sage_rtu_firmware sage_1410 sage_1430 sage_1450 sage_2400 sage_3030_magnum sage_4400 sage_4040- Published: Jun. 12, 2024
- Modified: Nov. 21, 2024