Latest CVE Feed
-
9.8
CRITICALCVE-2021-32619
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through `import()` or `new Worker` might have been able to bypass network and file system permission... Read more
Affected Products : deno- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-38172
perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian initially fixed this in 0.4.0-7.)... Read more
Affected Products : perm- Published: Feb. 05, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32607
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call HtmlUtils.SanitizeHtml on a private message.... Read more
Affected Products : smartstore- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25352
The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** This vulnerability derives from an incomplete fix for [CVE-2020-28283](https://security.snyk.io/vuln/SNYK-JS-LIBNESTED-1054930)... Read more
Affected Products : libnested- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-5299
A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure (PPS) before 5.4R4, leading to memory corruption and possibly remote code execution.... Read more
- Published: Jan. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25492
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.... Read more
Affected Products : hospital_management_system- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25494
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.... Read more
Affected Products : online_banking_system- Published: Mar. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3287
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.... Read more
Affected Products : manageengine_opmanager- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32959
Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06... Read more
Affected Products : suitelink- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32992
FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory buffer, which may allow an attacker to execute arbitrary code.... Read more
Affected Products : winproladder- Published: Jun. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-3897
An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SM... Read more
Affected Products : nextscale_n1200_enclosure_firmware thinkagile_hx_enclosure_certified_node_firmware thinkagile_vx_enclosure_firmware thinksystem_d2_enclosure_firmware nextscale_fan_power_controller_firmware nextscale_n1200_enclosure thinkagile_hx_enclosure_certified_node thinkagile_vx_enclosure thinksystem_d2_enclosure nextscale_fan_power_controller- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-25914
The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.... Read more
Affected Products : jib- Published: Sep. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26100
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system.... Read more
Affected Products : sapcar- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26112
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default fro... Read more
Affected Products : pinot- Published: Sep. 23, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2020-11530
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in the id GET parameter supplied to get_script/index.php, and allows an attacker to execute arbitrary SQL queries in the context of the WP... Read more
Affected Products : chop_slider- Published: May. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26133
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated at... Read more
Affected Products : bitbucket_data_center- Published: Apr. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26170
Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.... Read more
Affected Products : simple_mobile_comparison_website- Published: Mar. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-26284
Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the manage_client endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.... Read more
Affected Products : simple_client_management_system- Published: Mar. 21, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34165
A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.... Read more
Affected Products : basic_shopping_cart- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-27341
JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.... Read more
Affected Products : jfinalcms- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024