Latest CVE Feed
-
9.8
CRITICALCVE-2017-20179
A vulnerability was found in InSTEDD Pollit 2.3.1. It has been rated as critical. This issue affects the function TourController of the file app/controllers/tour_controller.rb. The manipulation leads to an unknown weakness. The attack may be initiated rem... Read more
Affected Products : pollit- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25157
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (... Read more
- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-7129
A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_employee_attendance_single. The manipulation of the argument ID leads to sql in... Read more
Affected Products : payroll_management_system- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-24093
An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.... Read more
- Published: Feb. 22, 2023
- Modified: Mar. 12, 2025
-
9.8
CRITICALCVE-2023-24114
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.... Read more
Affected Products : typecho- Published: Feb. 22, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2022-2504
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection.This issue affects SDD-Baro: before 2.8.432. ... Read more
Affected Products : sdd-baro- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2024
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.... Read more
Affected Products : gogs- Published: Feb. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1038
A vulnerability classified as critical has been found in SourceCodester Online Reviewer Management System 1.0. Affected is an unknown function of the file /reviewer_0/admins/assessments/pretest/questions-view.php. The manipulation of the argument id leads... Read more
Affected Products : online_reviewer_management_system- Published: Feb. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24206
Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function.... Read more
Affected Products : davinci- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25234
Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.... Read more
- Published: Feb. 27, 2023
- Modified: Mar. 10, 2025
-
9.8
CRITICALCVE-2023-24253
Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.... Read more
Affected Products : ikon_server- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0511
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1... Read more
Affected Products : java_policy_agents- Published: Feb. 28, 2023
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2023-20946
In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interactio... Read more
Affected Products : android- Published: Feb. 28, 2023
- Modified: Mar. 21, 2025
-
9.8
CRITICALCVE-2023-1100
A vulnerability classified as critical has been found in SourceCodester Online Catering Reservation System 1.0. This affects an unknown part of the file /reservation/add_message.php of the component POST Parameter Handler. The manipulation of the argument... Read more
Affected Products : online_catering_reservation_system- Published: Feb. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-22751
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploit... Read more
- Published: Mar. 01, 2023
- Modified: Mar. 07, 2025
-
9.8
CRITICALCVE-2023-1151
A vulnerability was found in SourceCodester Electronic Medical Records System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file administrator.php of the component Cookie Handler. The manipulation... Read more
Affected Products : electronic_medical_records_system- Published: Mar. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26779
CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).... Read more
Affected Products : yf-exam- Published: Mar. 03, 2023
- Modified: Mar. 06, 2025
-
9.8
CRITICALCVE-2022-4328
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server... Read more
Affected Products : woocommerce_checkout_field_manager- Published: Mar. 06, 2023
- Modified: Mar. 04, 2025
-
9.8
CRITICALCVE-2021-36392
In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.... Read more
Affected Products : moodle- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0755
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code. ... Read more
- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024