Latest CVE Feed
-
9.8
CRITICALCVE-2021-32163
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.... Read more
Affected Products : modular_open_smart_network- Published: Feb. 17, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-1499
A vulnerability classified as critical was found in code-projects Simple Art Gallery 1.0. Affected by this vulnerability is an unknown functionality of the file adminHome.php. The manipulation of the argument reach_city leads to sql injection. The attack ... Read more
Affected Products : simple_art_gallery- Published: Mar. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5143
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000 up to 20151231. This issue affects some unknown processing of the file /log/webmailattach.php. The manipulation of the argument table_name... Read more
- Published: Sep. 24, 2023
- Modified: Mar. 06, 2025
-
9.8
CRITICALCVE-2016-7043
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther servi... Read more
Affected Products : kie-server- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46414
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.... Read more
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46411
TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.... Read more
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3314
A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php. The manipulation leads to sql injection. The attack may be initiat... Read more
- Published: Apr. 04, 2024
- Modified: Jan. 22, 2025
-
9.8
CRITICALCVE-2023-46535
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getResetVeriRegister.... Read more
- Published: Oct. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27585
Password recovery vulnerability in SICK SIM1000 FX Partnumber 1097816 and 1097817 with firmware version <1.6.0 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mecha... Read more
- Published: Nov. 01, 2022
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2016-10329
Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to execute arbitrary code via shell metacharacters in the crafted 'X-Forwarded-For' header.... Read more
Affected Products : photo_station- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2009-4581
Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the admin parameter.... Read more
Affected Products : roseonlinecms- Published: Jan. 06, 2010
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2021-32608
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does not call HtmlUtils.SanitizeHtml on certain text for a forum post.... Read more
Affected Products : smartstore- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-33325
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger ... Read more
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9515
Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.... Read more
Affected Products : dozer- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-54136
ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/upload.php where the user supplied input via collection ge... Read more
Affected Products : clipbucket- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
9.8
CRITICALCVE-2023-4444
A vulnerability classified as critical was found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this vulnerability is an unknown functionality of the file vm\patient\edit-user.php. The manipulation of the argument i... Read more
Affected Products : free_hospital_management_system_for_small_practices- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-2564
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.... Read more
Affected Products : mongoose- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41507
Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.... Read more
Affected Products : super_store_finder- Published: Sep. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-46741
CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive data from the logs which could allow them escalate privileges. CubeFS leaks configuration keys i... Read more
Affected Products : cubefs- Published: Jan. 03, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41563
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.... Read more
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024