Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2020-13638

    lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.... Read more

    Affected Products : rconfig
    • Published: Nov. 13, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40828

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.... Read more

    Affected Products : codeigniter
    • Published: Oct. 07, 2022
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2023-3076

    The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.... Read more

    Affected Products : mstore_api
    • Published: Jul. 10, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40943

    Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.... Read more

    Affected Products : dairy_farm_shop_management_system
    • Published: Sep. 30, 2022
    • Modified: May. 20, 2025
  • 9.8

    CRITICAL
    CVE-2022-46072

    Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.... Read more

    Affected Products : helmet_store_showroom
    • Published: Dec. 14, 2022
    • Modified: Apr. 22, 2025
  • 9.8

    CRITICAL
    CVE-2022-46102

    AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php... Read more

    Affected Products : ayacms
    • Published: Dec. 22, 2022
    • Modified: Apr. 15, 2025
  • 9.8

    CRITICAL
    CVE-2023-31143

    mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72 with user authentication enabled may be affected by a vulnerability. The terminal could be accessed by us... Read more

    Affected Products : mage-ai
    • Published: May. 09, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-46593

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the do_sta_enrollee_wifi function.... Read more

    Affected Products : tew-755ap_firmware tew-755ap
    • Published: Dec. 30, 2022
    • Modified: Apr. 11, 2025
  • 9.8

    CRITICAL
    CVE-2022-41400

    Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection strings stored in ISAM database files in the shared data directory. This issue could allow attackers to decrypt user passwords and SQL co... Read more

    Affected Products : sage_300
    • Published: Apr. 28, 2023
    • Modified: Jan. 30, 2025
  • 9.8

    CRITICAL
    CVE-2022-41443

    phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.... Read more

    Affected Products : phpipam
    • Published: Oct. 03, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-41495

    ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.... Read more

    Affected Products : clippercms
    • Published: Oct. 13, 2022
    • Modified: May. 15, 2025
  • 9.8

    CRITICAL
    CVE-2023-31457

    A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.... Read more

    Affected Products : mivoice_connect
    • Published: May. 24, 2023
    • Modified: Jan. 31, 2025
  • 9.8

    CRITICAL
    CVE-2022-46954

    Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_transaction.... Read more

    • Published: Jan. 13, 2023
    • Modified: Apr. 07, 2025
  • 9.8

    CRITICAL
    CVE-2023-31814

    D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.... Read more

    Affected Products : dir-300_firmware dir-300
    • Published: May. 23, 2023
    • Modified: Jan. 17, 2025
  • 9.8

    CRITICAL
    CVE-2022-47445

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Web-X Be POPIA Compliant be-popia-compliant allows SQL Injection.This issue affects Be POPIA Compliant: from n/a through 1.2.0. ... Read more

    Affected Products : be-popia-compliant
    • Published: Nov. 03, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-32227

    Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials... Read more

    Affected Products : synergy\/a_firmware synergy\/a
    • Published: Jul. 30, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-42042

    The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.... Read more

    Affected Products : d8s-networking
    • Published: Oct. 11, 2022
    • Modified: May. 19, 2025
  • 9.8

    CRITICAL
    CVE-2021-42665

    An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.... Read more

    Affected Products : engineers_online_portal
    • Published: Nov. 05, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-47862

    Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.... Read more

    Affected Products : lead_management_system
    • Published: Jan. 11, 2023
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2023-3249

    The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possi... Read more

    • Published: Jun. 30, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 292811 Results