Latest CVE Feed
-
9.8
CRITICALCVE-2023-27973
Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.... Read more
Affected Products : laserjet_pro_m304-m305_w1a46a_firmware laserjet_pro_m304-m305_w1a47a_firmware laserjet_pro_m304-m305_w1a48a_firmware laserjet_pro_m304-m305_w1a66a_firmware laserjet_pro_m404-m405_93m22a_firmware laserjet_pro_m404-m405_w1a51a_firmware laserjet_pro_m404-m405_w1a52a_firmware laserjet_pro_m404-m405_w1a53a_firmware laserjet_pro_m404-m405_w1a56a_firmware laserjet_pro_m404-m405_w1a57a_firmware +66 more products- Published: Apr. 28, 2023
- Modified: Jan. 30, 2025
-
9.8
CRITICALCVE-2023-26781
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.... Read more
Affected Products : mccms- Published: Apr. 28, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2023-2479
OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4.... Read more
Affected Products : appium-desktop- Published: May. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2520
A vulnerability was found in Caton Prime 2.1.2.51.e8d7225049(202303031001) and classified as critical. This issue affects some unknown processing of the file cgi-bin/tools_ping.cgi?action=Command of the component Ping Handler. The manipulation of the argu... Read more
Affected Products : caton_prime- Published: May. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2524
A vulnerability classified as critical has been found in Control iD RHiD 23.3.19.0. This affects an unknown part of the file /v2/#/. The manipulation leads to direct request. It is possible to initiate the attack remotely. The associated identifier of thi... Read more
Affected Products : rhid- Published: May. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30264
CLTPHP <=6.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via application/admin/controller/Template.php:update.... Read more
Affected Products : cltphp- Published: May. 04, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-30053
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.... Read more
- Published: May. 05, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-29944
Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be executed at the custom code snippet function of the metersphere system workbench... Read more
Affected Products : metersphere- Published: May. 08, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-25754
Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.... Read more
Affected Products : airflow- Published: May. 08, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2023-24507
AgilePoint NX v8.0 SU2.2 & SU2.3 – Insecure File Upload - Vulnerability allows insecure file upload, by an unspecified request. ... Read more
Affected Products : agilepoint_nx- Published: May. 08, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2023-29460
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow poten... Read more
- Published: May. 09, 2023
- Modified: Dec. 17, 2024
-
9.8
CRITICALCVE-2023-2642
A vulnerability classified as critical has been found in SourceCodester Online Exam System 1.0. This affects an unknown part of the file adminpanel/admin/facebox_modal/updateCourse.php of the component GET Parameter Handler. The manipulation of the argume... Read more
- Published: May. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2669
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been classified as critical. This affects an unknown part of the file admin/?page=categories/view_category of the component GET Parameter Handler. The manipulation o... Read more
Affected Products : lost_and_found_information_system- Published: May. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27823
An authentication bypass in Optoma 1080PSTX C02 allows an attacker to access the administration console without valid credentials.... Read more
- Published: May. 12, 2023
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2023-2696
A vulnerability was found in SourceCodester Online Exam System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /matkul/data of the component POST Parameter Handler. The manipulation of the argument columns[1][dat... Read more
- Published: May. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29961
D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,... Read more
- Published: May. 16, 2023
- Modified: Jan. 23, 2025
-
9.8
CRITICALCVE-2023-31890
An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter.... Read more
Affected Products : glazed_lists- Published: May. 16, 2023
- Modified: Jan. 23, 2025
-
9.8
CRITICALCVE-2023-31729
TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.... Read more
- Published: May. 18, 2023
- Modified: Jan. 22, 2025
-
9.8
CRITICALCVE-2023-30333
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.... Read more
Affected Products : perfreeblog- Published: May. 18, 2023
- Modified: Jan. 23, 2025
-
9.8
CRITICALCVE-2023-2823
A vulnerability was found in SourceCodester Class Scheduling System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit_subject.php of the component GET Parameter Handler. The manipulat... Read more
Affected Products : class_scheduling_system- Published: May. 20, 2023
- Modified: Nov. 21, 2024