Latest CVE Feed
-
9.8
CRITICALCVE-2022-40030
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.... Read more
Affected Products : simple_task_managing_system- Published: Sep. 21, 2022
- Modified: May. 28, 2025
-
9.8
CRITICALCVE-2022-2070
In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by openi... Read more
- Published: Sep. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-41438
The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to change this by SSHing into the device, it has remained unchanged on every installed system observed. This account is not root but holds... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2020-36846
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a ... Read more
Affected Products :- Published: May. 30, 2025
- Modified: May. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2022-40484
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.... Read more
Affected Products : wedding_planner- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-37346
EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image f... Read more
Affected Products : product_image_bulk_upload- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-41570
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.... Read more
Affected Products : eyesofnetwork- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-41571
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.... Read more
Affected Products : eyesofnetwork- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-39033
Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access rest... Read more
Affected Products : smart_evision- Published: Sep. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-5387
A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to improper access controls. It is poss... Read more
Affected Products : jeewms- Published: May. 31, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-47530
Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels allows Object Injection. This issue affects WPFunnels: from n/a through 3.5.18.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2020-15331
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.... Read more
Affected Products : cloudcnm_secumanager- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-5432
A vulnerability has been found in AssamLook CMS 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_tender.php. The manipulation of the argument ID leads to sql injection. The attack can be launched... Read more
Affected Products : assamlook_cms- Published: Jun. 02, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-20672
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00412257... Read more
Affected Products : mt7902_firmware mt7921_firmware mt7902 mt7921 mt7927 mt7922 mt7925 mt7922_firmware mt7925_firmware mt7927_firmware- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5442
A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_pingGatewayByBBS of the file /goform... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5445
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RP_checkFWByBBS of the file /goform/RP_checkF... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-37095
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2022-40721
Arbitrary file upload vulnerability in php uploader... Read more
Affected Products : creativedream_file_uploader- Published: Oct. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-9091
A vulnerability was found in code-projects Student Record System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument regno leads to sql injection. The a... Read more
Affected Products : student_record_system- Published: Sep. 23, 2024
- Modified: Sep. 27, 2024
-
9.8
CRITICALCVE-2022-40830
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.... Read more
Affected Products : codeigniter- Published: Oct. 07, 2022
- Modified: Nov. 21, 2024