Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2020-24199

    Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.... Read more

    Affected Products : car_rental_project
    • Published: Sep. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-44938

    Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.... Read more

    Affected Products : seeddms
    • Published: Dec. 08, 2022
    • Modified: Apr. 23, 2025
  • 9.8

    CRITICAL
    CVE-2020-24231

    Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBean methods. It is possible to install additional MBeans ... Read more

    Affected Products : symmetricds
    • Published: Oct. 05, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-29778

    GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.... Read more

    Affected Products : gl-mt3000_firmware gl-mt3000
    • Published: May. 02, 2023
    • Modified: Jan. 30, 2025
  • 9.8

    CRITICAL
    CVE-2022-40111

    In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.... Read more

    Affected Products : a3002r_firmware a3002r
    • Published: Sep. 06, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-45297

    EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.... Read more

    Affected Products : eq
    • Published: Jan. 31, 2023
    • Modified: Mar. 27, 2025
  • 9.8

    CRITICAL
    CVE-2023-30192

    Prestashop possearchproducts 1.7 is vulnerable to SQL Injection via PosSearch::find().... Read more

    Affected Products : possearchproducts
    • Published: May. 12, 2023
    • Modified: Jan. 27, 2025
  • 9.8

    CRITICAL
    CVE-2022-44929

    An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.... Read more

    • Published: Dec. 02, 2022
    • Modified: Apr. 24, 2025
  • 9.8

    CRITICAL
    CVE-2022-40431

    The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.... Read more

    Affected Products : d8s-pdfs
    • Published: Sep. 19, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2023-30470

    A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d9810633502f65ed462b819c09 could have been used by an attacker to achieve remote code execution. Note that thi... Read more

    Affected Products : hermes
    • Published: May. 18, 2023
    • Modified: Jan. 21, 2025
  • 9.8

    CRITICAL
    CVE-2022-45564

    SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet.... Read more

    • Published: Feb. 21, 2023
    • Modified: Mar. 17, 2025
  • 9.8

    CRITICAL
    CVE-2022-3414

    A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. Affected is an unknown function of the file /Admin/login.php of the component POST Parameter Handler. The manipulation of the argument txtu... Read more

    • Published: Oct. 07, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-6928

    PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.... Read more

    Affected Products : news_website_script
    • Published: Feb. 13, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2020-13638

    lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.... Read more

    Affected Products : rconfig
    • Published: Nov. 13, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40828

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.... Read more

    Affected Products : codeigniter
    • Published: Oct. 07, 2022
    • Modified: Apr. 09, 2025
  • 9.8

    CRITICAL
    CVE-2023-3076

    The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.... Read more

    Affected Products : mstore_api
    • Published: Jul. 10, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2022-40943

    Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.... Read more

    Affected Products : dairy_farm_shop_management_system
    • Published: Sep. 30, 2022
    • Modified: May. 20, 2025
  • 9.8

    CRITICAL
    CVE-2022-46072

    Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.... Read more

    Affected Products : helmet_store_showroom
    • Published: Dec. 14, 2022
    • Modified: Apr. 22, 2025
  • 9.8

    CRITICAL
    CVE-2022-46102

    AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php... Read more

    Affected Products : ayacms
    • Published: Dec. 22, 2022
    • Modified: Apr. 15, 2025
  • 9.8

    CRITICAL
    CVE-2023-31143

    mage-ai is an open-source data pipeline tool for transforming and integrating data. Those who use Mage starting in version 0.8.34 and prior to 0.8.72 with user authentication enabled may be affected by a vulnerability. The terminal could be accessed by us... Read more

    Affected Products : mage-ai
    • Published: May. 09, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 294210 Results