Latest CVE Feed
-
9.8
CRITICALCVE-2020-10666
The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL variable to an AMI command.... Read more
- Published: May. 31, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10508
The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validatin... Read more
Affected Products : registrationmagic- Published: Nov. 09, 2024
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2024-24754
Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda event is converted to a PSR7 object. During the conversion process, if the request is a Mult... Read more
Affected Products : bref- Published: Feb. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8149
Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.... Read more
Affected Products : logkitty- Published: May. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-4073
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_... Read more
Affected Products : registrationmagic- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-39205
Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The /git-prereceive-callback endpoint is u... Read more
Affected Products : onedev- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31329
Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.... Read more
Affected Products : online_ordering_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10084
A vulnerability was found in irontec klear-library chloe and classified as critical. Affected by this issue is the function _prepareWhere of the file Controller/Rest/BaseController.php. The manipulation leads to sql injection. Upgrading to version marla i... Read more
Affected Products : klear-library- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31343
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/?page=bookings/view_details&id=.... Read more
Affected Products : online_car_wash_booking_system- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-31356
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.... Read more
Affected Products : online_ordering_system- Published: Jun. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31276
Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.8.... Read more
Affected Products : products\,_order_\&_customers_export_for_woocommerce- Published: Jun. 09, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-42769
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter. ... Read more
Affected Products : analog_fm_transmitter_exc5000gx_firmware analog_fm_transmitter_exc120gx_firmware analog_fm_transmitter_exc300gx_firmware analog_fm_transmitter_exc1600gx_firmware analog_fm_transmitter_exc2000gx_firmware analog_fm_transmitter_exc1000gx_firmware analog_fm_transmitter_exc3000gx_firmware analog_fm_transmitter_exc30gt_firmware analog_fm_transmitter_exc300gt_firmware analog_fm_transmitter_exc100gt_firmware +20 more products- Published: Oct. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8349
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled.... Read more
- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-10083
A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. Thi... Read more
Affected Products : dynosaur-rails- Published: Feb. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36061
Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between contracts can generate smart contracts results. For example, if contract A calls in read only mode contract B and the called function ... Read more
Affected Products : elrond_go- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-36812
OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration... Read more
Affected Products : opentsdb- Published: Jun. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-3087
A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this issue is some unknown functionality of the file ambulance-tracking.php of the component Ambulance Tracking Page. The ma... Read more
Affected Products : emergency_ambulance_hiring_portal- Published: Mar. 30, 2024
- Modified: Feb. 14, 2025
-
9.8
CRITICALCVE-2015-10035
A vulnerability was found in gperson angular-test-reporter and classified as critical. This issue affects the function getProjectTables/addTest of the file rest-server/data-server.js. The manipulation leads to sql injection. The patch is named a29d8ae121b... Read more
Affected Products : angular-test-reporter- Published: Jan. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2429
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.13.... Read more
Affected Products : phpmyfaq- Published: Apr. 30, 2023
- Modified: Jan. 30, 2025
-
9.8
CRITICALCVE-2024-25077
An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-fly decryption of flash images is stored in an unsigned header, allowing its value to be modified without invalidating the signature use... Read more
Affected Products :- Published: Jul. 10, 2024
- Modified: Nov. 21, 2024