Latest CVE Feed
-
9.8
CRITICALCVE-2017-5586
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.... Read more
Affected Products : documentum_d2- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-36560
Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.... Read more
Affected Products : phone_shop_sales_management_system- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5878
While sending the response to a RIL_REQUEST_GET_SMSC_ADDRESS message, a buffer overflow can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear.... Read more
Affected Products : sd_625_firmware sd_835_firmware mdm9650_firmware mdm9206_firmware mdm9607_firmware mdm9635m_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_615_firmware +14 more products- Published: Jul. 06, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28722
Certain HP Print Products are potentially vulnerable to Buffer Overflow.... Read more
Affected Products : j9v82a_firmware j6u55a_firmware j6u55b_firmware j9v80a_firmware d3q15a_firmware d3q17a_firmware d3q19a_firmware d3q20a_firmware d3q21a_firmware k9z76a_firmware +188 more products- Published: Sep. 26, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2021-41644
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.... Read more
Affected Products : online_food_ordering_system- Published: Oct. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29077
A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or execute commands remotely on a rippled node, which may lead to XRPL mainnet DoS or compromise. This exposes all digital assets on the XRPL ... Read more
Affected Products : rippled- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11789
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.... Read more
Affected Products : r6700_firmware r6900_firmware r6400_firmware r7900_firmware r6400 r6700 r6900 r7900- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37413
GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content a... Read more
Affected Products : dynweb- Published: May. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37599
The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection that allows a remote, unauthenticated attacker to read the database (and execute code in some situations) via the txtPassword paramete... Read more
Affected Products : winscribe_dictation- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29496
A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerabi... Read more
Affected Products : blynk-library- Published: Jun. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29745
Money Transfer Management System 1.0 is vulnerable to SQL Injection via \mtms\classes\Master.php?f=delete_transaction.... Read more
Affected Products : money_transfer_management_system- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43090
An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function.... Read more
Affected Products : soa_model- Published: Mar. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5014
A vulnerability was found in Sakshi2610 Food Ordering Website 1.0 and classified as critical. This issue affects some unknown processing of the file categoryfood.php. The manipulation of the argument id leads to sql injection. The attack may be initiated ... Read more
Affected Products : food_ordering_website- Published: Sep. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30455
Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id.... Read more
Affected Products : badminton_center_management_system- Published: May. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38697
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.... Read more
Affected Products : saraban- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-4032
IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the... Read more
Affected Products : financial_transaction_manager- Published: Mar. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-19213
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.... Read more
Affected Products : piwigo- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18869
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.... Read more
Affected Products : empirecms- Published: Oct. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-39655
Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A... Read more
Affected Products : android- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45459
lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.... Read more
Affected Products : node-windows- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024