Latest CVE Feed
-
9.8
CRITICALCVE-2020-10539
An issue was discovered in Epikur before 20.1.1. The Epikur server contains the checkPasswort() function that, upon user login, checks the submitted password against the user password's MD5 hash stored in the database. It is also compared to a second MD5 ... Read more
Affected Products : epikur- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13859
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to the cgi... Read more
- Published: Feb. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11742
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.... Read more
- Published: Dec. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22223
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function.... Read more
Affected Products : fundraising_script- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11212
Out of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Indu... Read more
- Published: Jan. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-18716
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.... Read more
Affected Products : rockoa- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11800
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.... Read more
Affected Products : fineract- Published: Jun. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8027
Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.... Read more
Affected Products : camel- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27234
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. The web application suffers from SQL injection on Adminlog.asp, Archivemsgs.asp, Deletelog.asp, Eventlog.asp, and Evmlog.asp.... Read more
Affected Products : voice- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23377
This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input saniti... Read more
Affected Products : onion-oled-js- Published: Apr. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-37478
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.... Read more
- Published: Jul. 26, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45691
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.... Read more
Affected Products : messagepack-rs- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9374
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.... Read more
- Published: Feb. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32337
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=.... Read more
Affected Products : hospital\'s_patient_records_management_system- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29989
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_booking.... Read more
Affected Products : online_sports_complex_booking_system- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30476
Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetFirewallCfg request.... Read more
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34601
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm.... Read more
- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10292
A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the file 3/Ebak5.1/upload/ChangeTable.php. The manipulation of the argument savefilename leads to unrestricted upload. The attack may be init... Read more
Affected Products : zzcms- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2022-35150
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.... Read more
Affected Products : baijiacms- Published: Aug. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35153
FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.... Read more
Affected Products : fusionpbx- Published: Aug. 18, 2022
- Modified: Nov. 21, 2024