Latest CVE Feed
-
9.8
CRITICALCVE-2020-22819
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.... Read more
Affected Products : mkcms- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2020-13167
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.... Read more
Affected Products : netsweeper- Published: May. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-6639
An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d.... Read more
Affected Products : mathtype- Published: Feb. 28, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38325
Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.... Read more
- Published: Sep. 15, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28667
The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or veri... Read more
Affected Products : lead_generated- Published: Mar. 22, 2023
- Modified: Feb. 25, 2025
-
9.8
CRITICALCVE-2022-43762
Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages ... Read more
Affected Products : industrial_automation_aprol- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-23691
YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.... Read more
Affected Products : yfcmf- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44096
Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.... Read more
Affected Products : sanitization_management_system- Published: Nov. 30, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44048
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-domains package. The affected version of d8s-htm is 0.... Read more
Affected Products : d8s-urls- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-44176
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.... Read more
- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2020-13417
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.... Read more
- Published: May. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-24199
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.... Read more
Affected Products : car_rental_project- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44938
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.... Read more
Affected Products : seeddms- Published: Dec. 08, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2020-24231
Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans ... Read more
Affected Products : symmetricds- Published: Oct. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29778
GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.... Read more
- Published: May. 02, 2023
- Modified: Jan. 30, 2025
-
9.8
CRITICALCVE-2022-40111
In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.... Read more
- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-45297
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.... Read more
Affected Products : eq- Published: Jan. 31, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2023-30192
Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().... Read more
Affected Products : possearchproducts- Published: May. 12, 2023
- Modified: Jan. 27, 2025
-
9.8
CRITICALCVE-2022-44929
An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2022-40431
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.... Read more
Affected Products : d8s-pdfs- Published: Sep. 19, 2022
- Modified: Nov. 21, 2024