Latest CVE Feed
-
9.8
CRITICALCVE-2023-28667
The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or veri... Read more
Affected Products : lead_generated- Published: Mar. 22, 2023
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2022-43762
Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages ... Read more
Affected Products : industrial_automation_aprol- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23691
YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.... Read more
Affected Products : yfcmf- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44096
Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.... Read more
Affected Products : sanitization_management_system- Published: Nov. 30, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44048
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.... Read more
Affected Products : d8s-urls- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44176
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.... Read more
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2020-13417
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.... Read more
- Published: May. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-24199
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.... Read more
Affected Products : car_rental_project- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44938
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.... Read more
Affected Products : seeddms- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2020-24231
Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans ... Read more
Affected Products : symmetricds- Published: Oct. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29778
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.... Read more
- Published: May. 02, 2023
- Modified: Jan. 30, 2025
-
9.8
CRITICALCVE-2022-40111
In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.... Read more
- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45297
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.... Read more
Affected Products : eq- Published: Jan. 31, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2023-30192
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().... Read more
Affected Products : possearchproducts- Published: May. 12, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2022-44929
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2022-40431
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.... Read more
Affected Products : d8s-pdfs- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30470
A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d9810633502f65ed462b819c09 could have been used by an attacker to achieve remote code execution. Note that thi... Read more
Affected Products : hermes- Published: May. 18, 2023
- Modified: Jan. 21, 2025
-
9.8
CRITICALCVE-2022-45564
SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet.... Read more
Affected Products : home_improvement_erp_management_system- Published: Feb. 21, 2023
- Modified: Mar. 17, 2025
-
9.8
CRITICALCVE-2022-3414
A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. Affected is an unknown function of the file /Admin/login.php of the component POST Parameter Handler. The manipulation of the argument txtu... Read more
- Published: Oct. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6928
PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.... Read more
Affected Products : news_website_script- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024