Latest CVE Feed
-
9.8
CRITICALCVE-2023-50026
SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGrou... Read more
Affected Products : multi_accessories_pro- Published: Feb. 09, 2024
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2019-18847
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.... Read more
Affected Products : enterprise_application_access- Published: Aug. 26, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-45466
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.... Read more
- Published: Oct. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-20520
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution. ... Read more
Affected Products : epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware +116 more products- Published: May. 09, 2023
- Modified: Jan. 28, 2025
-
9.8
CRITICALCVE-2023-33270
An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).... Read more
Affected Products : monitoring- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33271
An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind).... Read more
Affected Products : monitoring- Published: Oct. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19836
AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.... Read more
Affected Products : zonedirector_1200_firmware unleashed r310 zonedirector_1200 h320 h510 r710 r720 t610 r510 +7 more products- Published: Jan. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17890
NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arbitrary code execution.... Read more
Affected Products : nuuo_cms- Published: Oct. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45805
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3. ... Read more
Affected Products : payment_gateway- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-11645
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 do not require authentication for logfile.html, status.html, or system_config.html.... Read more
- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-23623
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` in that directiv... Read more
Affected Products : electron- Published: Sep. 06, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-18007
atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials.... Read more
- Published: Dec. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-40811
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.... Read more
Affected Products : democritus_urls- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36779
PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Proscend M330-w / M33-W5 / M350-5G / M350-W5G / M350-6 / M350-W6 / M301-G / M301-GW ADVICE ICR 111WG / https://www.proscend.com/en/categor... Read more
Affected Products : m350-5g_firmware m350-w5g_firmware m350-6_firmware m350-w6_firmware m330-w_firmware m330-w5_firmware m301-g_firmware m301-gw_firmware icr_111wg_firmware m330-w +8 more products- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0680
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to read/send mail or change the configuration.... Read more
- Published: Nov. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3878
A vulnerability classified as critical has been found in Maxon ERP. This affects an unknown part of the file /index.php/purchase_order/browse_data. The manipulation of the argument tb_search leads to sql injection. It is possible to initiate the attack re... Read more
Affected Products : maxon- Published: Nov. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6859
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter.... Read more
Affected Products : schools_alert_management_script- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41566
The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.... Read more
Affected Products : tadtools- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3734
A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The attack can be initia... Read more
- Published: Oct. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-37173
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.... Read more
- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024