Latest CVE Feed
-
9.8
CRITICALCVE-2020-25782
An issue was discovered on Accfly Wireless Security IR Camera 720P System with software versions v3.10.73 through v4.15.77. There is an unauthenticated stack-based buffer overflow in the function CNetClientManage::ServerIP_Proto_Set during incoming messag... Read more
- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1908
A vulnerability was found in SourceCodester Simple Mobile Comparison Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/categories/view_category.php of the component GET Parameter Handler. The manipulation ... Read more
Affected Products : simple_mobile_comparison_website- Published: Apr. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-4933
A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection... Read more
Affected Products : dolibarr_module_quicksupplierprice- Published: Mar. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37999
Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.... Read more
Affected Products : ht_mega- Published: May. 17, 2024
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2021-40870
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.... Read more
Affected Products : controller- Actively Exploited
- Published: Sep. 13, 2021
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2022-4963
A vulnerability was found in Folio Spring Module Core up to 1.1.5. It has been rated as critical. Affected by this issue is the function dropSchema of the file tenant/src/main/java/org/folio/spring/tenant/hibernate/HibernateSchemaService.java of the compo... Read more
Affected Products : spring_module_core- Published: Mar. 21, 2024
- Modified: Mar. 05, 2025
-
9.8
CRITICALCVE-2023-39666
D-Link DIR-842 fw_revA_1-02_eu_multi_20151008 was discovered to contain multiple buffer overflows in the fgets function via the acStack_120 and acStack_220 parameters.... Read more
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40041
TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code.... Read more
- Published: Aug. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-20873
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x user... Read more
Affected Products : spring_boot- Published: Apr. 20, 2023
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2023-40266
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.... Read more
Affected Products : unify_openscape_xpressions_webassistant- Published: Feb. 08, 2024
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2023-2106
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.... Read more
- Published: Apr. 15, 2023
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2022-38308
TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.... Read more
- Published: Sep. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0345
The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password cannot be changed by the user.... Read more
- Published: Mar. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40300
NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.... Read more
Affected Products : ngeniuspulse- Published: Dec. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0570
A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects an unknown part of the file user\operations\payment_operation.php. The manipulation of the argument booking_id leads ... Read more
- Published: Jan. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0663
A vulnerability was found in Calendar Event Management System 2.3.0. It has been rated as critical. This issue affects some unknown processing of the component Login Page. The manipulation of the argument name/pwd leads to sql injection. The attack may be... Read more
Affected Products : calendar_event_management_system- Published: Feb. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0754
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code. ... Read more
- Published: Feb. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0839
Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Account Footprinting.This issue affects inSCADA: before 20230115-1. ... Read more
Affected Products : inscada- Published: Mar. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41558
Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter timeZone at url /goform/SetSysTimeCfg.... Read more
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4186
A vulnerability was found in SourceCodester Pharmacy Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manage_website.php. The manipulation leads to unrestricted upload. The att... Read more
Affected Products : pharmacy_management_system- Published: Aug. 06, 2023
- Modified: Nov. 21, 2024