Latest CVE Feed
-
9.8
CRITICALCVE-2022-48284
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.... Read more
Affected Products : hilink_ai_life- Published: Feb. 27, 2023
- Modified: Mar. 11, 2025
-
9.8
CRITICALCVE-2022-48479
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.... Read more
Affected Products : harmonyos- Published: May. 26, 2023
- Modified: Jan. 15, 2025
-
9.8
CRITICALCVE-2022-48334
Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and resultant buffer overflow.... Read more
Affected Products : trusted_application- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43003
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.... Read more
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-43103
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.... Read more
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-4880
A vulnerability was found in stakira OpenUtau. It has been classified as critical. This affects the function VoicebankInstaller of the file OpenUtau.Core/Classic/VoicebankInstaller.cs of the component ZIP Archive Handler. The manipulation leads to path tr... Read more
Affected Products : openutau- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43262
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.... Read more
- Published: Nov. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33362
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.... Read more
Affected Products : piwigo- Published: May. 23, 2023
- Modified: Apr. 16, 2025
-
9.8
CRITICALCVE-2023-33338
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.... Read more
Affected Products : old_age_home_management_system- Published: May. 23, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2022-4395
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.... Read more
Affected Products : membership_for_woocommerce- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2022-44051
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.... Read more
Affected Products : d8s-stats- Published: Nov. 07, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2020-14054
SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows remote attackers to bypass admin authentication via a SQL injection attack that uses the User Name or Password field on the login page.... Read more
- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44199
Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.... Read more
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-44371
hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).... Read more
Affected Products : hope-boot- Published: Dec. 07, 2022
- Modified: Apr. 23, 2025
-
9.8
CRITICALCVE-2022-34605
H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /dotrace.asp.... Read more
- Published: Jul. 20, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34128
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.... Read more
- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34213
TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentially allow malici... Read more
- Published: Aug. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34952
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php.... Read more
Affected Products : pharmacy_management_system- Published: Aug. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-44808
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can proces... Read more
- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2021-35414
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.... Read more
Affected Products : chamilo_lms- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024