Latest CVE Feed
-
9.8
CRITICALCVE-2022-23795
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.... Read more
Affected Products : joomla\!- Published: Mar. 30, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45756
Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.... Read more
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-16232
In Yokogawa WideField3 R1.01 - R4.03, a buffer overflow could be caused when a user loads a maliciously crafted project file.... Read more
Affected Products : widefield3- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-14982
Certain LG devices based on Android 6.0 through 8.1 have incorrect access control in the GNSS application. The LG ID is LVE-SMP-180004.... Read more
- Published: Aug. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-20392
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.... Read more
Affected Products : imcat- Published: Jun. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10651
An issue was discovered in the Core Server in Ivanti Endpoint Manager (EPM) 2017.3 before SU7 and 2018.x before 2018.3 SU3, with remote code execution. In other words, the issue affects 2017.3, 2018.1, and 2018.3 installations that lack the April 2019 upd... Read more
Affected Products : endpoint_manager- Published: Jul. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12196
A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.... Read more
Affected Products : manageengine_netflow_analyzer- Published: Jun. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29045
The food-and-drink-menu plugin through 2.2.0 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the fdm_cart cookie in load_cart_from_cookie in includes/class-cart-manager.php.... Read more
Affected Products : five_star_restaurant_menu- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2160
Weak Password Requirements in GitHub repository modoboa/modoboa prior to 2.1.0. ... Read more
Affected Products : modoboa- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-47213
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR... Read more
Affected Products : cfr-1004ea_firmware cfr-1008ea_firmware cfr-1016ea_firmware cfr-16eaa_firmware cfr-16eab_firmware cfr-16eha_firmware cfr-16ehd_firmware cfr-4eaa_firmware cfr-4eaam_firmware cfr-4eab_firmware +46 more products- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-36108
casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sensitive information via GET request to an API endpoint. This issue has been addressed in PR #201 which is pe... Read more
Affected Products :- Published: May. 31, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22668
Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.... Read more
Affected Products : cncsoft_screeneditor- Published: May. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3232
A vulnerability was found in Zhong Bang CRMEB up to 4.6.0 and classified as critical. This issue affects some unknown processing of the file /api/wechat/app_auth of the component Image Upload. The manipulation leads to deserialization. The exploit has bee... Read more
Affected Products : crmeb- Published: Jun. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32752
L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform ... Read more
- Published: Jun. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24140
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function.... Read more
- Published: Feb. 03, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2015-7224
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.... Read more
Affected Products : puppetlabs-mysql- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-9320
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.... Read more
Affected Products : businessobjects_edge- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27444
The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attacker to remotely access and download sensitive information and perform administrative actions on behalf of a legitimate administrator.... Read more
Affected Products : cmt-svr-100_firmware cmt-svr-102_firmware cmt-svr-200_firmware cmt-svr-202_firmware cmt-g01_firmware cmt-g02_firmware cmt-g03_firmware cmt-g04_firmware cmt3071_firmware cmt3072_firmware +22 more products- Published: May. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-29751
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client.... Read more
Affected Products : simple_client_management_system- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-10899
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : a-reserve- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025