Latest CVE Feed
-
9.8
CRITICALCVE-2020-19778
Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulating the parameter "user_id" in the HTML request.... Read more
Affected Products : shopxo- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33139
A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configurati... Read more
- Published: Jun. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33171
The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injec... Read more
Affected Products : typeorm- Published: Jul. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41928
SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.... Read more
Affected Products : try_my_recipe- Published: Jan. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24084
ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.... Read more
Affected Products : chikoi- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
9.8
CRITICALCVE-2023-24205
Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).... Read more
Affected Products : clash- Published: Feb. 23, 2023
- Modified: Mar. 12, 2025
-
9.8
CRITICALCVE-2022-34059
The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : sixfab-tool- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34061
The Catly-Translate package in PyPI v0.0.3 to v0.0.5 was discovered to contain a code execution backdoor. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.... Read more
Affected Products : catly_translate- Published: Jun. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-39198
A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and pri... Read more
Affected Products : dubbo- Published: Oct. 18, 2022
- Modified: May. 13, 2025
-
9.8
CRITICALCVE-2022-39305
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Versions prior to 2.5.4 contain a file upload ability. The affected code fails to validate fileMd5 and fileName parameters, resultin... Read more
Affected Products : gin-vue-admin- Published: Oct. 24, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34501
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.... Read more
Affected Products : pypi- Published: Jul. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34555
TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet.... Read more
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24997
Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apach... Read more
Affected Products : inlong- Published: Feb. 01, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2022-3465
A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of the file /index.asp. The manipulation leads to improper authentication. The attack can be initiated remotely. The exploit has been disclo... Read more
- Published: Oct. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40089
A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.... Read more
Affected Products : simple_college_website- Published: Sep. 22, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-34954
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php.... Read more
Affected Products : pharmacy_management_system- Published: Aug. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34949
Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php.... Read more
Affected Products : pharmacy_management_system- Published: Aug. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-4336
IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411.... Read more
Affected Products : robotic_process_automation_with_automation_anywhere- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35201
Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.... Read more
- Published: Aug. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35426
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.... Read more
Affected Products : ucms- Published: Aug. 10, 2022
- Modified: Nov. 21, 2024