Latest CVE Feed
-
9.8
CRITICALCVE-2024-10964
A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow. It is possible... Read more
Affected Products : neuron- Published: Nov. 07, 2024
- Modified: Nov. 26, 2024
-
9.8
CRITICALCVE-2023-5974
The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.... Read more
Affected Products : wpb_show_core- Published: Nov. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-52040
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.... Read more
- Published: Jan. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-6412
A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via photo.php in multiple parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted... Read more
Affected Products : voovi- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31024
NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code e... Read more
- Published: Jan. 12, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20987
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.... Read more
Affected Products : newsletters- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3777
The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.... Read more
Affected Products : qbibot- Published: Apr. 15, 2024
- Modified: Apr. 08, 2025
-
9.8
CRITICALCVE-2023-3077
The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to g... Read more
Affected Products : mstore_api- Published: Jul. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-1264
A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability is the function actionUpdate of the file /api/controllers/common/UploadsController.php. The manipulation of the argument imgage leads ... Read more
Affected Products : jpshop- Published: Feb. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0363
A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to... Read more
Affected Products : hospital_management_system hospital_management_system hospital_management_system- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-12960
A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. This issue affects some unknown processing of the file /update_edu_details.php. The manipulation of the argument q leads to sql injecti... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 26, 2024
- Modified: Feb. 28, 2025
-
9.8
CRITICALCVE-2024-0540
A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. Affected is the function formOfflineSet of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to lau... Read more
- Published: Jan. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-38879
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). The affected system exposes the port of an internal application on the public net... Read more
Affected Products : omnivise_t3000_application_server- Published: Aug. 02, 2024
- Modified: Sep. 20, 2024
-
9.8
CRITICALCVE-2021-24951
The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in SQL statements when duplicating course/lesson/quiz/question, leading to SQL Injections issues... Read more
Affected Products : learnpress- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0715
Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03. ... Read more
- Published: Feb. 20, 2024
- Modified: Feb. 12, 2025
-
9.8
CRITICALCVE-2024-0738
A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function ExpressionEngine of the file com/mldong/modules/wf/engine/model/DecisionModel.java. The manipulation leads to code injection. The attack ... Read more
Affected Products : mldong- Published: Jan. 19, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51928
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : yonbip- Published: Jan. 20, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2019-6296
Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter.... Read more
Affected Products : cleanto- Published: Jan. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-39619
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through 2.9.3.... Read more
Affected Products : listingpro- Published: Aug. 01, 2024
- Modified: Aug. 02, 2024
-
9.8
CRITICALCVE-2024-0939
A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the file /Tool/uploadfile.php. The manipulation of the argument file_upload leads to unrestricted... Read more
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024