Latest CVE Feed
-
9.8
CRITICALCVE-2022-26969
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.... Read more
Affected Products : directus- Published: Dec. 26, 2022
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2022-48079
Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.... Read more
Affected Products : aapanel_host_system- Published: Feb. 02, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2022-48108
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.... Read more
- Published: Jan. 27, 2023
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2022-46809
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPDeveloper ReviewX – Multi-criteria Rating & Reviews for WooCommerce.This issue affects ReviewX – Multi-criteria Rating & Reviews for WooCommerce: from n/a through 1.6.7. ... Read more
Affected Products : reviewx- Published: Nov. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38942
Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.... Read more
Affected Products : dango-translator- Published: Aug. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39013
Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init.... Read more
Affected Products : duke- Published: Jul. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-46957
Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.... Read more
Affected Products :- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
9.8
CRITICALCVE-2023-44015
Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the setSchedWifi function.... Read more
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28862
In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify query syntax and perform unauthorized ... Read more
Affected Products : web_central- Published: May. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44163
The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database. ... Read more
Affected Products : online_movie_ticket_booking_system- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-5064
A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack ... Read more
Affected Products : online_course_registration_system- Published: May. 17, 2024
- Modified: Mar. 03, 2025
-
9.8
CRITICALCVE-2025-2952
A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknown functionality of the file /api/api.php?mod=upload&type=1. The manipulation of the argument File leads to unrestricted upload. The att... Read more
Affected Products : micro_mall- Published: Mar. 30, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2023-4419
The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.... Read more
- Published: Aug. 24, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45981
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.... Read more
Affected Products : ngeniusone- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-51259
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.... Read more
- Published: Oct. 31, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2024-51255
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function.... Read more
- Published: Oct. 31, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2023-4436
A vulnerability, which was classified as critical, has been found in SourceCodester Inventory Management System 1.0. This issue affects some unknown processing of the file app/action/edit_update.php. The manipulation of the argument user_id leads to sql i... Read more
- Published: Aug. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-51327
SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.... Read more
Affected Products : travel_management_system- Published: Nov. 04, 2024
- Modified: Nov. 06, 2024
-
9.8
CRITICALCVE-2024-47849
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.... Read more
Affected Products : cargo- Published: Oct. 05, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-21495
Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be predicted via a brute-force search. Attackers could use the po... Read more
Affected Products : caddy-security- Published: Feb. 17, 2024
- Modified: Nov. 21, 2024