Latest CVE Feed
-
9.8
CRITICALCVE-2022-36695
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.... Read more
Affected Products : ingredients_stock_management_system- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36709
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/edit_book_details.php.... Read more
Affected Products : library_management_system- Published: Aug. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37813
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the function fromSetSysTime.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36683
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment.... Read more
Affected Products : simple_task_scheduling_system- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-42171
Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.... Read more
- Published: Oct. 17, 2022
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2022-38314
Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.... Read more
- Published: Sep. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-35296
An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via modification of the cookie value and Response Path.... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37092
H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAPWifiorLedInfoById.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47865
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.... Read more
Affected Products : lead_management_system- Published: Jan. 11, 2023
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2023-36340
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.... Read more
- Published: Oct. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38861
An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.... Read more
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41560
Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter firewallEn at url /goform/SetFirewallCfg.... Read more
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32518
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32520. Affected Products: Data Center Ex... Read more
Affected Products : data_center_expert- Published: Jan. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4760
In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. The reason for this is a not completely secure extraction of the file name in the FileUploadProcessor.st... Read more
Affected Products : remote_application_platform- Published: Sep. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-32563
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase... Read more
Affected Products : sync_gateway- Published: Jun. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21855
A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.... Read more
Affected Products : gocast- Published: Nov. 21, 2024
- Modified: Dec. 20, 2024
-
9.8
CRITICALCVE-2024-2573
A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file /task-info.php. The manipulation leads to execution after redirect. It is possible to launch the attac... Read more
- Published: Mar. 18, 2024
- Modified: Feb. 20, 2025
-
9.8
CRITICALCVE-2023-31129
The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message handling code for IPv6 router solicitiations. Contiki-NG contains an implementation of IPv6 Neighbor Discovery (ND) in the module `os/net/... Read more
Affected Products : contiki-ng- Published: May. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27952
An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbitrary code via a crafted SVG file.... Read more
Affected Products : payload- Published: Apr. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1701
A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. The manipulation leads to improper access controls. The attack can b... Read more
Affected Products : php_mysql_user_signup_login_system- Published: Feb. 21, 2024
- Modified: Feb. 12, 2025