Latest CVE Feed
-
9.8
CRITICALCVE-2024-0537
A vulnerability, which was classified as critical, was found in Tenda W9 1.0.0.7(4456). This affects the function setWrlBasicInfo of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to in... Read more
- Published: Jan. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0541
A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. Affected by this vulnerability is the function formAddSysLogRule of the component httpd. The manipulation of the argument sysRulenEn leads to stack-based buffer overflo... Read more
- Published: Jan. 15, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-1869
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php.... Read more
Affected Products : best_online_news_portal- Published: Mar. 03, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-6765
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function prepare of the file email_setup.php. The manipulation of the argument name leads to sql injection. The... Read more
Affected Products : online_tours_\&_travels_management_system online_tours_\&travels_management_system- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0576
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been declared as critical. This vulnerability affects the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument sPort leads to stack-ba... Read more
- Published: Jan. 16, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-31689
In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, ... Read more
Affected Products : wcms- Published: May. 22, 2023
- Modified: Jan. 28, 2025
-
9.8
CRITICALCVE-2023-51018
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi.... Read more
- Published: Dec. 22, 2023
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-0714
A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file userScripts.php of the component HTTP Request Handler. The manipulation of the argument fol... Read more
Affected Products : phoniebox- Published: Jan. 19, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0414
A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation leads to improper access controls. It is possible to launch the attack remotely. Th... Read more
Affected Products : dscms- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-36548
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http ge... Read more
Affected Products : fortiwlm- Published: Oct. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-3656
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to... Read more
Affected Products : cashit\!- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0884
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec of the file payment.php. The manipulation of the argument id leads to sql injection. The attack m... Read more
Affected Products : online_tours_\&_travels_management_system online_tours_\&travels_management_system- Published: Jan. 25, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0988
A vulnerability classified as critical was found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this vulnerability is the function checklogin of the file /application/index/common.php. The manipulation of the argument App_User_id/App_user_Tok... Read more
Affected Products : kuerp- Published: Jan. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32284
An out-of-bounds write vulnerability exists in the tiff_planar_adobe functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : imagegear- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43286
Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c.... Read more
Affected Products : njs- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2020-24193
A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.... Read more
Affected Products : daily_tracker_system- Published: Sep. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51717
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.... Read more
Affected Products : data_science_studio- Published: Jan. 09, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2024-10170
A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. This issue affects some unknown processing of the file get_doctor.php. The manipulation of the argument specilizationid leads to sql injecti... Read more
- Published: Oct. 20, 2024
- Modified: Oct. 21, 2024
-
9.8
CRITICALCVE-2025-2473
A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Sign In. The manipulation of the argument username leads... Read more
Affected Products : company_visitor_management_system- Published: Mar. 18, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-10291
A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_DoExecSQL/Ebak_DotranExecutSQL of the file 3/Ebak5.1/upload/phome.php. The manipulation of the argument phome leads to sql injection. The... Read more
Affected Products : zzcms- Published: Oct. 23, 2024
- Modified: Oct. 30, 2024