Latest CVE Feed
-
9.8
CRITICALCVE-2022-3457
Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.... Read more
Affected Products : rdiffweb- Published: Oct. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-3458
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulatio... Read more
Affected Products : human_resource_management_system- Published: Oct. 12, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43185
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.... Read more
Affected Products : youtrack- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-1967
Keysight N8844A Data Analytics Web Service deserializes untrusted data without sufficiently verifying the resulting data will be valid. ... Read more
Affected Products : n8844a- Published: Apr. 27, 2023
- Modified: Jan. 16, 2025
-
9.8
CRITICALCVE-2021-43193
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.... Read more
Affected Products : teamcity- Published: Nov. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-41522
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.... Read more
- Published: Oct. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39560
ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.... Read more
Affected Products : ectouch- Published: Aug. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39642
Carts Guru cartsguru up to v2.4.2 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::display().... Read more
Affected Products : cartsguru- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39668
D-Link DIR-868L fw_revA_1-12_eu_multi_20170316 was discovered to contain a buffer overflow via the param_2 parameter in the inet_ntoa() function.... Read more
- Published: Aug. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39851
webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be u... Read more
Affected Products : webchess- Published: Aug. 15, 2023
- Modified: Jul. 03, 2025
-
9.8
CRITICALCVE-2021-22387
There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to remotely execute commands.... Read more
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40163
An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulne... Read more
Affected Products : imagegear- Published: Sep. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0324
A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql... Read more
- Published: Jan. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6168
A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.... Read more
- Published: Jun. 26, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2149
A vulnerability classified as critical was found in Campcodes Online Thesis Archiving System 1.0. This vulnerability affects unknown code of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can b... Read more
Affected Products : online_thesis_archiving_system- Published: Apr. 18, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0693
The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to a... Read more
Affected Products : master_elements- Published: Apr. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-38937
Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list pa... Read more
Affected Products : ac6_firmware ac9_firmware ac10_firmware ac7_firmware ac1206_firmware ac5_firmware ac8_firmware ac6 ac8 ac10 +4 more products- Published: Aug. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0744
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.... Read more
Affected Products : answer- Published: Feb. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-41364
In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.... Read more
Affected Products : tine- Published: Sep. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4257
Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.... Read more
Affected Products : zephyr- Published: Oct. 13, 2023
- Modified: Nov. 21, 2024