Latest CVE Feed
-
9.8
CRITICALCVE-2022-46892
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.... Read more
- Published: Feb. 15, 2023
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2023-23460
Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.... Read more
Affected Products : priority- Published: Feb. 15, 2023
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2020-21119
SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.... Read more
Affected Products : kliqqi_cms- Published: Feb. 15, 2023
- Modified: Mar. 20, 2025
-
9.8
CRITICALCVE-2023-24238
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.... Read more
- Published: Feb. 16, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2025-7831
A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unknown part of the file /members/Tithes.php. The manipulation of the argument trcode leads to sql injection. It is possible to initiate the... Read more
Affected Products : church_donation_system- Published: Jul. 19, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2020-29168
SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.... Read more
Affected Products : online_doctor_appointment_booking_system_php_and_mysql- Published: Feb. 17, 2023
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2023-23064
TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.... Read more
- Published: Feb. 17, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2022-48328
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.... Read more
Affected Products : misp- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-10019
A vulnerability was found in OCLC-Research OAICat 1.5.61. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.5.62 is able to addr... Read more
Affected Products : oaicat- Published: Feb. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25613
An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. ... Read more
- Published: Feb. 20, 2023
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2023-23452
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.... Read more
- Published: Feb. 20, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-23453
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.... Read more
- Published: Feb. 20, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2022-45677
SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.... Read more
Affected Products : tuition_management_system- Published: Feb. 21, 2023
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2017-20179
A vulnerability was found in InSTEDD Pollit 2.3.1. It has been rated as critical. This issue affects the function TourController of the file app/controllers/tour_controller.rb. The manipulation leads to an unknown weakness. The attack may be initiated rem... Read more
Affected Products : pollit- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25157
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (... Read more
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-7129
A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_employee_attendance_single. The manipulation of the argument ID leads to sql in... Read more
Affected Products : payroll_management_system- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-24093
An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.... Read more
- Published: Feb. 22, 2023
- Modified: Mar. 12, 2025
-
9.8
CRITICALCVE-2023-24114
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.... Read more
Affected Products : typecho- Published: Feb. 22, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2022-2504
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection.This issue affects SDD-Baro: before 2.8.432. ... Read more
Affected Products : sdd-baro- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2024
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.... Read more
Affected Products : gogs- Published: Feb. 25, 2023
- Modified: Nov. 21, 2024