Latest CVE Feed
-
9.8
CRITICALCVE-2022-37070
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22226
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.... Read more
Affected Products : fundraising_script- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28424
Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/search.go`, are affected by a SQL injection via the `q` parameter. As a result, ... Read more
Affected Products : soko- Published: Mar. 20, 2023
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2022-38296
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.... Read more
Affected Products : cuppacms- Published: Sep. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43672
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.... Read more
Affected Products : manageengine_password_manager_pro manageengine_pam360 manageengine_access_manager_plus- Published: Nov. 12, 2022
- Modified: May. 01, 2025
-
9.8
CRITICALCVE-2022-38828
TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi... Read more
- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38880
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The affected version is 0.1.0.... Read more
Affected Products : democritus_urls- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41100
Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address change of a user with only the short-lived session token in the `Authorization` header. As the short-live... Read more
- Published: Oct. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44188
Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.... Read more
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2020-23790
An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.... Read more
Affected Products : golo- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44365
Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2020-23976
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.... Read more
Affected Products : ecommerce_cms- Published: Aug. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3940
A vulnerability, which was classified as problematic, was found in lanyulei ferry. This affects an unknown part of the file apis/process/task.go. The manipulation of the argument file_name leads to path traversal. The associated identifier of this vulnera... Read more
Affected Products : ferry- Published: Nov. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-24133
A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.... Read more
Affected Products : radare2-extras- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29665
D-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.... Read more
- Published: Apr. 17, 2023
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2015-2081
Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.... Read more
Affected Products : alto_3_firmware alto_2_firmware alto_xl_firmware siris_3_firmware siris_2_firmware siris_3_x_all-flash_firmware siris_virtual_firmware alto_imaged_firmware alto_3 alto_2 +6 more products- Published: Feb. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-4050
The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users... Read more
Affected Products : joomsport- Published: Dec. 19, 2022
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2022-45482
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H... Read more
Affected Products : lazy_mouse- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025