Latest CVE Feed
-
9.8
CRITICALCVE-2022-37199
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.... Read more
Affected Products : jfinal_cms- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37204
Final CMS 5.1.0 is vulnerable to SQL Injection.... Read more
Affected Products : jfinal_cms- Published: Sep. 20, 2022
- Modified: May. 27, 2025
-
9.8
CRITICALCVE-2022-37223
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.... Read more
Affected Products : jfinal_cms- Published: Aug. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22253
Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitr... Read more
- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-22819
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.... Read more
Affected Products : mkcms- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2020-13167
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.... Read more
Affected Products : netsweeper- Published: May. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6639
An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d.... Read more
Affected Products : mathtype- Published: Feb. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38325
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.... Read more
- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28667
The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or veri... Read more
Affected Products : lead_generated- Published: Mar. 22, 2023
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2022-43762
Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages ... Read more
Affected Products : industrial_automation_aprol- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23691
YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.... Read more
Affected Products : yfcmf- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44096
Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.... Read more
Affected Products : sanitization_management_system- Published: Nov. 30, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44048
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.... Read more
Affected Products : d8s-urls- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44176
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.... Read more
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2020-13417
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.... Read more
- Published: May. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-24199
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.... Read more
Affected Products : car_rental_project- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44938
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.... Read more
Affected Products : seeddms- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2020-24231
Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans ... Read more
Affected Products : symmetricds- Published: Oct. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29778
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.... Read more
- Published: May. 02, 2023
- Modified: Jan. 30, 2025
-
9.8
CRITICALCVE-2022-40111
In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.... Read more
- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024