Latest CVE Feed
-
9.8
CRITICALCVE-2021-22388
There is an Integer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.... Read more
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-2302
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker ... Read more
Affected Products : platform_security_for_java- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24150
A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.... Read more
- Published: Feb. 03, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2023-24052
An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.... Read more
- Published: Dec. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24166
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.... Read more
- Published: Jan. 26, 2023
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2023-24199
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.... Read more
Affected Products : raffle_draw_system- Published: Feb. 06, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2023-24033
The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.... Read more
- Published: Mar. 13, 2023
- Modified: Mar. 03, 2025
-
9.8
CRITICALCVE-2023-24643
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php.... Read more
Affected Products : judging_management_system- Published: Mar. 03, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24775
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.... Read more
Affected Products : funadmin- Published: Mar. 07, 2023
- Modified: Mar. 05, 2025
-
9.8
CRITICALCVE-2023-24236
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.... Read more
- Published: Feb. 16, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2023-24796
Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary code via the password parameter at the /goform/sysTools and /adm/systools.asp endpoints.... Read more
- Published: Apr. 26, 2023
- Modified: Feb. 03, 2025
-
9.8
CRITICALCVE-2023-21130
In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitati... Read more
Affected Products : android- Published: Jun. 15, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-21494
Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.... Read more
- Published: May. 04, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4542
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possibl... Read more
- Published: Aug. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-34914
Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For header can be manipu... Read more
Affected Products : webswing- Published: Jul. 08, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-27183
A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges of arbitrary user accounts, and have unspecified other ... Read more
Affected Products : publixone- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43693
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.... Read more
Affected Products : vesta_control_panel- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0982
The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereby user input cmdline_len is copied into a fixed buffer b->buf without any bound checks. If the server connects with a malicious client,... Read more
Affected Products : accel-ppp- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26512
CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq mess... Read more
- Published: Jul. 17, 2023
- Modified: Jun. 25, 2025
-
9.8
CRITICALCVE-2023-4677
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the... Read more
Affected Products : pandora_fms- Published: Nov. 23, 2023
- Modified: Nov. 21, 2024