Latest CVE Feed
-
9.8
CRITICALCVE-2022-35598
A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter username.... Read more
Affected Products : inventorymanagementsystem- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26109
All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation. ... Read more
Affected Products : node-bluetooth-serial-port- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40994
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequ... Read more
- Published: Jan. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3574
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.... Read more
Affected Products : wpforms_pro- Published: Nov. 14, 2022
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-4126
Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects RCCMD: before 4.40 230207. ... Read more
- Published: Mar. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-19126
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.... Read more
Affected Products : prestashop- Published: Nov. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-41578
The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.... Read more
- Published: Oct. 14, 2022
- Modified: May. 14, 2025
-
9.8
CRITICALCVE-2023-27060
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.... Read more
Affected Products : lightcms- Published: Mar. 22, 2023
- Modified: Feb. 26, 2025
-
9.8
CRITICALCVE-2023-27229
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the upBw parameter at /setting/setWanIeCfg.... Read more
- Published: Mar. 28, 2023
- Modified: Feb. 18, 2025
-
9.8
CRITICALCVE-2023-27224
An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.... Read more
Affected Products : nginx_proxy_manager- Published: Mar. 22, 2023
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2018-6548
A use-after-free issue was discovered in libwebm through 2018-02-02. If a Vp9HeaderParser was initialized once before, its property frame_ would not be changed because of code in vp9parser::Vp9HeaderParser::SetFrame. Its frame_ could be freed while the co... Read more
Affected Products : libwebm- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36712
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/studentdetails.php.... Read more
Affected Products : library_management_system- Published: Aug. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36725
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /student/dele.php.... Read more
Affected Products : library_management_system- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36756
DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.... Read more
- Published: Aug. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36759
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.... Read more
Affected Products : online_food_ordering_system- Published: Sep. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-42021
Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=.... Read more
Affected Products : best_student_result_management_system- Published: Oct. 20, 2022
- Modified: May. 08, 2025
-
9.8
CRITICALCVE-2020-21935
A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.... Read more
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27603
In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.... Read more
Affected Products : linkis- Published: Apr. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36787
webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE. ... Read more
Affected Products : webvendome- Published: Nov. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-42163
Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.... Read more
- Published: Oct. 17, 2022
- Modified: May. 15, 2025