Latest CVE Feed
-
9.8
CRITICALCVE-2024-24122
A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a zip compressed file to construct a special file name, which can be used to decompress the project f... Read more
Affected Products : edraw- Published: Oct. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-7824
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2... Read more
Affected Products : secureanywhere_web_shield- Published: Oct. 03, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-7826
Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.... Read more
Affected Products : secureanywhere_web_shield- Published: Oct. 03, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-43699
Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain records contained in the targeted product.... Read more
Affected Products : diaenergie- Published: Oct. 03, 2024
- Modified: Oct. 08, 2024
-
9.8
CRITICALCVE-2024-47656
This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to ga... Read more
- Published: Oct. 04, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-9536
A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /MultiServerBackService?path=1. The manipulation of the argument fileId leads to sql injection. The attack may be... Read more
Affected Products : cdg- Published: Oct. 05, 2024
- Modified: May. 16, 2025
-
9.8
CRITICALCVE-2024-20100
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Iss... Read more
- Published: Oct. 07, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-46076
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.... Read more
Affected Products : ruoyi- Published: Oct. 07, 2024
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2022-22810
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (... Read more
Affected Products : spacelynk_firmware wiser_for_knx_firmware fellerlynk_firmware spacelynk wiser_for_knx fellerlynk- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-45873
A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Yaazhini.exe.... Read more
Affected Products :- Published: Oct. 07, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2022-24311
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Data Server potentially leading to re... Read more
Affected Products : interactive_graphical_scada_system_data_server- Published: Feb. 09, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-46361
An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.... Read more
Affected Products : magnolia_cms- Published: Feb. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-47823
Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actua... Read more
Affected Products : livewire- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
9.8
CRITICALCVE-2024-9796
The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks... Read more
Affected Products : wp-advanced-search- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9793
A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the function ate_iwpriv_set/ate_ifconfig_set of the file /goform/ate. The manipulation leads to command injection. The attack can be initiated r... Read more
- Published: Oct. 10, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-9813
A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0. This issue affects some unknown processing of the file product/register.php. The manipulation of the argument category leads to sql injection. Th... Read more
Affected Products : pharmacy_management_system- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9818
A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affected is an unknown function of the file /admin/categories/manage_category.php. The manipulation of the argument id leads to sql injection... Read more
Affected Products : online_veterinary_appointment_system- Published: Oct. 10, 2024
- Modified: Oct. 17, 2024
-
9.8
CRITICALCVE-2024-42640
angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-46088
An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9916
A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file app/modules/ut-cac/admin/cli.php. The manipulation of the argument o leads to os command injection. Th... Read more
Affected Products : usualtoolcms- Published: Oct. 13, 2024
- Modified: Oct. 16, 2024