Latest CVE Feed
-
9.8
CRITICALCVE-2022-46640
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.... Read more
Affected Products : nanoleaf_desktop- Published: Apr. 18, 2023
- Modified: Feb. 06, 2025
-
9.8
CRITICALCVE-2024-45695
The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.... Read more
- Published: Sep. 16, 2024
- Modified: Sep. 17, 2024
-
9.8
CRITICALCVE-2023-41355
Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resul... Read more
- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-43534
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.... Read more
Affected Products : qca6391_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6155p_firmware sa8155p_firmware sa8195p_firmware wcd9380_firmware wcd9385_firmware wsa8830_firmware +124 more products- Published: Feb. 06, 2024
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2022-2774
A vulnerability was found in SourceCodester Library Management System. It has been declared as critical. This vulnerability affects unknown code of the file librarian/student.php. The manipulation of the argument title leads to sql injection. The attack c... Read more
Affected Products : library_management_system- Published: Aug. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-45999
A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter.... Read more
Affected Products : cloudlog- Published: Oct. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-46377
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.... Read more
Affected Products : best_house_rental_management_system- Published: Sep. 18, 2024
- Modified: Apr. 16, 2025
-
9.8
CRITICALCVE-2024-46419
TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.... Read more
- Published: Sep. 16, 2024
- Modified: Sep. 17, 2024
-
9.8
CRITICALCVE-2023-41561
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.... Read more
- Published: Aug. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47003
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.... Read more
Affected Products : mura_cms- Published: Feb. 01, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2023-4183
A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit_update.php of the component Password Handler. The manipulation of the argument user_id... Read more
- Published: Aug. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47034
A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.... Read more
Affected Products : playsms- Published: Feb. 13, 2023
- Modified: Mar. 21, 2025
-
9.8
CRITICALCVE-2024-42565
ERP commit 44bd04 was discovered to contain a SQL injection vulnerability via the id parameter at /index.php/basedata/contact/delete?action=delete.... Read more
- Published: Aug. 20, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2022-47071
In NVS365 V01, the background network test function can trigger command execution.... Read more
- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2024-42638
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.... Read more
- Published: Aug. 16, 2024
- Modified: Mar. 17, 2025
-
9.8
CRITICALCVE-2024-42745
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.... Read more
- Published: Aug. 12, 2024
- Modified: Aug. 13, 2024
-
9.8
CRITICALCVE-2024-42777
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
Affected Products : music_management_system- Published: Aug. 21, 2024
- Modified: Aug. 23, 2024
-
9.8
CRITICALCVE-2024-46997
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.... Read more
Affected Products : dataease- Published: Sep. 23, 2024
- Modified: Oct. 07, 2024
-
9.8
CRITICALCVE-2019-9594
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.... Read more
- Published: Mar. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-44880
A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more
- Published: May. 20, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection