Latest CVE Feed
-
9.8
CRITICALCVE-2024-25217
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.... Read more
Affected Products : online_medicine_ordering_system- Published: Feb. 14, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2024-25222
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.... Read more
Affected Products : task_manager_in_php_with_source_code- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27157
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.... Read more
Affected Products : pearweb- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-28811
In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.... Read more
- Published: Sep. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26205
Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.... Read more
Affected Products : marky- Published: Mar. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31788
IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.... Read more
Affected Products : idealms- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11422
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted... Read more
Affected Products : oncell_g3150-hspa_firmware oncell_g3150-hspa-t_firmware oncell_g3150-hspa-t oncell_g3150-hspa- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3183
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability. ... Read more
- Published: Dec. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48315
Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components incl... Read more
Affected Products : azure_rtos_netx_duo- Published: Dec. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4832
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Management allows SQL Injection.This issue affects Company Management: before 3072 . ... Read more
Affected Products : company_management- Published: Sep. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45359
Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.... Read more
Affected Products : yith_woocommerce_gift_cards- Published: Dec. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27360
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.... Read more
Affected Products : springblade- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27477
Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.... Read more
Affected Products : newbee-mall- Published: Apr. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43504
A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an atta... Read more
Affected Products : comos- Published: Nov. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51892
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.... Read more
Affected Products : e-cology- Published: Jan. 20, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-4850
A vulnerability, which was classified as critical, was found in IBOS OA 4.5.5. This affects an unknown part of the file ?r=dashboard/position/del. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has bee... Read more
Affected Products : ibos- Published: Sep. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-13558
In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a system crash.... Read more
Affected Products : webaccess- Published: Sep. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43518
Memory corruption in video while parsing invalid mp2 clip.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6430_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware +302 more products- Published: Feb. 06, 2024
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2019-13577
SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string to the CE Remote feature listening on Port 987.... Read more
Affected Products : maple_computer_wbt_snmp_administrator- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1765
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akbim Computer Panon allows SQL Injection.This issue affects Panon: before 1.0.2. ... Read more
Affected Products : panon- Published: Apr. 03, 2023
- Modified: Nov. 21, 2024