Latest CVE Feed
-
9.8
CRITICALCVE-2024-36681
SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` and `pk_isotope::removeData` methods.... Read more
Affected Products :- Published: Jun. 24, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-7096
A vulnerability was found in code-projects Faculty Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/php/crud.php. The manipulation of the argument fieldname leads to sql injectio... Read more
Affected Products : faculty_management_system- Published: Dec. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-42303
An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a second-order SQL Injection attack affecting the NBFSMCLIENT service by leveraging CVE-2022-42302.... Read more
Affected Products : netbackup- Published: Oct. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9709
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a privilege escalation vulnerability exists in telephony.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-9933
The WatchTowerHQ plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.6. This is due to the 'watchtower_ota_token' default value is empty, and the not empty check is missing in the 'Password_Less_Access::login'... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2023-7161
A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. This affects an unknown part of the file index.php?para=index of the component Login. The manipulation of the argument check_VirtualSiteId leads ... Read more
- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-40691
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web interface. Attackers can make use of this weakness and upload malicious executable files into the system, ... Read more
Affected Products : cognos_controller- Published: Dec. 03, 2024
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2017-9785
Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.... Read more
Affected Products : nancy- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2024-9976
A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_customer.php?action=search. The manipulation of the argument text leads to sql injection. It is pos... Read more
Affected Products : pharmacy_management_system- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2023-3533
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file wr... Read more
- Published: Nov. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4078
A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises from the lack of path sanitization when handling the `name` par... Read more
Affected Products : lollms- Published: May. 16, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-6826
A vulnerability, which was classified as critical, has been found in code-projects Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /Payroll_Management_System/ajax.php?action=save_department. The manipulation... Read more
- Published: Jun. 28, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6962
A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects an unknown part of the file /myprofileup.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the... Read more
Affected Products : employee_management_system- Published: Jul. 01, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6934
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of ... Read more
Affected Products :- Published: Jul. 01, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-0244
Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series f... Read more
Affected Products : mf755cdw_firmware mf753cdw_firmware mf751cdw_firmware mf1333c_firmware lbp1333c_firmware i-sensys_mf754cdw_firmware i-sensys_x_c1333if_firmware mf755cdw mf753cdw mf751cdw +4 more products- Published: Feb. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28033
An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a certain deserialization method panics.... Read more
Affected Products : byte_struct- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28035
An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a drop of uninitialized memory can occur upon a val.clone() panic.... Read more
Affected Products : stack_dst- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-24637
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the in... Read more
Affected Products : open_web_analytics- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0359
A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injecti... Read more
- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0535
A vulnerability classified as critical was found in Tenda PA6 1.0.1.21. Affected by this vulnerability is the function cgiPortMapAdd of the file /portmap of the component httpd. The manipulation of the argument groupName leads to stack-based buffer overfl... Read more
- Published: Jan. 15, 2024
- Modified: Nov. 21, 2024