Latest CVE Feed
-
9.8
CRITICALCVE-2024-10119
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.... Read more
- Published: Oct. 18, 2024
- Modified: Nov. 01, 2024
-
9.8
CRITICALCVE-2024-10121
A vulnerability was found in wfh45678 Radar up to 1.0.8 and classified as critical. This issue affects some unknown processing of the component Interface Handler. The manipulation with the input /../ leads to authorization bypass. The attack may be initia... Read more
Affected Products : radar- Published: Oct. 18, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2024-10136
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_invoice.php. The manipulation of the argument invoice_number leads to sql injection. T... Read more
Affected Products : pharmacy_management_system- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2024-10153
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file book-boat.php?bid=1 of the component Book a Boat Page. The manipulation of the argument... Read more
Affected Products : boat_booking_system- Published: Oct. 19, 2024
- Modified: Mar. 16, 2025
-
9.8
CRITICALCVE-2024-10156
A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the component Sign In Page. The manipulation of the argument username leads to sql i... Read more
Affected Products : boat_booking_system- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2024-49328
Authentication Bypass Using an Alternate Path or Channel vulnerability in Vivek Tamrakar WP REST API FNS allows Authentication Bypass.This issue affects WP REST API FNS: from n/a through 1.0.0.... Read more
Affected Products : wp_rest_api_fns- Published: Oct. 20, 2024
- Modified: Oct. 23, 2024
-
9.8
CRITICALCVE-2024-49604
Authentication Bypass Using an Alternate Path or Channel vulnerability in Najeeb Ahmad Simple User Registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through 5.5.... Read more
Affected Products : simple_user_registration- Published: Oct. 20, 2024
- Modified: Oct. 23, 2024
-
9.8
CRITICALCVE-2024-49624
Deserialization of Untrusted Data vulnerability in Smartdevth Advanced Advertising System allows Object Injection.This issue affects Advanced Advertising System: from n/a through 1.3.1.... Read more
Affected Products : advanced_advertising_system- Published: Oct. 20, 2024
- Modified: Oct. 24, 2024
-
9.8
CRITICALCVE-2021-42787
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input val... Read more
Affected Products : steelcentral_appinternals_dynamic_sampling_agent- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-22814
The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.... Read more
Affected Products : myasus- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25818
Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.... Read more
- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24651
sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.... Read more
Affected Products : sentcms- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44620
A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.... Read more
- Published: Mar. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10138
A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. Affected is an unknown function of the file /add_new_purchase.php?action=is_supplier. The manipulation of the argument name leads to sql injection. It i... Read more
Affected Products : pharmacy_management_system- Published: Oct. 19, 2024
- Modified: Oct. 22, 2024
-
9.8
CRITICALCVE-2024-44812
SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.... Read more
Affected Products : online_complaint_site- Published: Oct. 22, 2024
- Modified: Oct. 25, 2024
-
9.8
CRITICALCVE-2024-10277
A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/ajax/UsbKeyAjax.java. The manipulation of the argument id leads to sql injection. The attack may... Read more
Affected Products : cdg- Published: Oct. 23, 2024
- Modified: Nov. 04, 2024
-
9.8
CRITICALCVE-2024-10293
A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of the file 3/Ebbak5.1/upload/class/functions.php. The manipulation of the argument file leads to unrestricted upload. It is possible to ... Read more
Affected Products : zzcms- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2022-24755
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, it will skip authorization chec... Read more
Affected Products : bareos- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48963
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory ... Read more
Affected Products : snyk_cli- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2022-26213
Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.... Read more
- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024