Latest CVE Feed
-
9.8
CRITICALCVE-2022-46954
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_transaction.... Read more
Affected Products : dynamic_transaction_queuing_system- Published: Jan. 13, 2023
- Modified: Apr. 07, 2025
-
9.8
CRITICALCVE-2023-31814
D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.... Read more
- Published: May. 23, 2023
- Modified: Jan. 17, 2025
-
9.8
CRITICALCVE-2022-47445
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Web-X Be POPIA Compliant be-popia-compliant allows SQL Injection.This issue affects Be POPIA Compliant: from n/a through 1.2.0. ... Read more
Affected Products : be-popia-compliant- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32227
Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials... Read more
- Published: Jul. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-42042
The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.... Read more
Affected Products : d8s-networking- Published: Oct. 11, 2022
- Modified: May. 19, 2025
-
9.8
CRITICALCVE-2021-42665
An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.... Read more
Affected Products : engineers_online_portal- Published: Nov. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-47862
Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.... Read more
Affected Products : lead_management_system- Published: Jan. 11, 2023
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2023-3249
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possi... Read more
Affected Products : web3_-_crypto_wallet_login_\&_nft_token_gating- Published: Jun. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-32567
Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236... Read more
Affected Products : avalanche- Published: Aug. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-48284
A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.... Read more
Affected Products : hilink_ai_life- Published: Feb. 27, 2023
- Modified: Mar. 11, 2025
-
9.8
CRITICALCVE-2022-48479
The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.... Read more
Affected Products : harmonyos- Published: May. 26, 2023
- Modified: Jan. 15, 2025
-
9.8
CRITICALCVE-2022-48334
Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and resultant buffer overflow.... Read more
Affected Products : trusted_application- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43003
D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.... Read more
- Published: Oct. 26, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-43103
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.... Read more
- Published: Nov. 03, 2022
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2022-4880
A vulnerability was found in stakira OpenUtau. It has been classified as critical. This affects the function VoicebankInstaller of the file OpenUtau.Core/Classic/VoicebankInstaller.cs of the component ZIP Archive Handler. The manipulation leads to path tr... Read more
Affected Products : openutau- Published: Jan. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-43262
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.... Read more
- Published: Nov. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-33362
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.... Read more
Affected Products : piwigo- Published: May. 23, 2023
- Modified: Apr. 16, 2025
-
9.8
CRITICALCVE-2023-33338
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.... Read more
Affected Products : old_age_home_management_system- Published: May. 23, 2023
- Modified: Jan. 31, 2025
-
9.8
CRITICALCVE-2022-4395
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.... Read more
Affected Products : membership_for_woocommerce- Published: Jan. 30, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2022-44051
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.... Read more
Affected Products : d8s-stats- Published: Nov. 07, 2022
- Modified: May. 05, 2025