Latest CVE Feed
-
9.8
CRITICALCVE-2022-20405
Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A... Read more
Affected Products : android- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31465
An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x ... Read more
Affected Products : timekeeper- Published: Jul. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31471
An issue was discovered on GL.iNet devices before 3.216. Through the software installation feature, it is possible to install arbitrary software, such as a reverse shell, because the restrictions on the available package list are limited to client-side ve... Read more
Affected Products : gl-e750_firmware gl-mt3000_firmware gl-mt1300_firmware gl-mt300n-v2_firmware gl-ar750s_firmware gl-ar750_firmware gl-ar300m_firmware gl-b1300_firmware gl-a1300_firmware gl-ax1800_firmware +54 more products- Published: May. 10, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2025-20055
OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can access the affected product may execute an arbitrary OS command.... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-0573
A vulnerability has been found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based... Read more
- Published: Jan. 16, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0574
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument sTime leads to stack-based buffer o... Read more
- Published: Jan. 16, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-2046
A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/print1.php. The manipulation of the argument id leads to sql injection. The... Read more
Affected Products : best_employee_management_system- Published: Mar. 06, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-31710
TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow.... Read more
- Published: Aug. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24881
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and... Read more
Affected Products : codegen- Published: Apr. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-36327
Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function.... Read more
Affected Products : relic- Published: Sep. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31903
GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.... Read more
Affected Products : guppy- Published: May. 17, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2024-0649
A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /app/Http/Controllers/ImageController.php of the component Search. The manipulation of the argument url lead... Read more
Affected Products : zhihuiyun- Published: Jan. 17, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43058
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.... Read more
Affected Products : online_diagnostic_lab_management_system- Published: Nov. 09, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2024-0921
A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setDeviceSettings of the component Web Interface. The manipulation of the argument sta... Read more
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0929
A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Affected by this issue is the function fromNatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be lau... Read more
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25095
Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.... Read more
Affected Products : home_owners_collection_management_system- Published: Feb. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43260
Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.... Read more
- Published: Oct. 18, 2022
- Modified: May. 12, 2025
-
9.8
CRITICALCVE-2022-43305
The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-algorithms package. The affected version of d8s-htm ... Read more
Affected Products : d8s-python- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-36947
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.... Read more
- Published: Oct. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25222
Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter.... Read more
Affected Products : money_transfer_management_system- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024