Latest CVE Feed
-
9.8
CRITICALCVE-2023-24219
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.... Read more
Affected Products : luckyframeweb- EPSS Score: %0.25
- Published: Feb. 17, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2021-34624
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affect... Read more
Affected Products : profilepress- EPSS Score: %0.92
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44348
SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class.php.... Read more
- EPSS Score: %0.26
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49750
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from ... Read more
Affected Products : couponis- EPSS Score: %0.17
- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29215
In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. T... Read more
Affected Products : linkis- EPSS Score: %3.11
- Published: Apr. 10, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2022-35846
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user v... Read more
Affected Products : fortitester- EPSS Score: %0.38
- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5008
Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.... Read more
- EPSS Score: %0.03
- Published: Dec. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-35865
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. ... Read more
Affected Products : track-it\!- EPSS Score: %18.09
- Published: Aug. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-25933
A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute arbitrary code via untrusted JavaScript. Note that this is only exploitable in cases where Hermes is used t... Read more
Affected Products : hermes- EPSS Score: %0.48
- Published: May. 18, 2023
- Modified: Jan. 21, 2025
-
9.8
CRITICALCVE-2023-5046
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Procost allows SQL Injection, Command Line Execution through SQL Injection.This issue affects Procost: before 1390. ... Read more
Affected Products : procost- EPSS Score: %0.07
- Published: Oct. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-50948
IBM Storage Fusion HCI 2.1.0 through 2.6.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Fo... Read more
Affected Products : storage_fusion_hci- EPSS Score: %0.07
- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5055
Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.... Read more
Affected Products : zephyr- EPSS Score: %0.50
- Published: Nov. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48929
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.... Read more
Affected Products : system_sentinel_anyware- EPSS Score: %0.07
- Published: Dec. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-31004
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.... Read more
Affected Products : bento4- Published: Apr. 02, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2023-0783
A vulnerability was found in EcShop 4.1.5. It has been classified as critical. This affects an unknown part of the file /ecshop/admin/template.php of the component PHP File Handler. The manipulation leads to unrestricted upload. It is possible to initiate... Read more
Affected Products : ecshop- EPSS Score: %0.06
- Published: Feb. 11, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44978
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.... Read more
Affected Products : icms- EPSS Score: %2.67
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36086
linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization methods were missing a minimum size check for the given heap size argument. This could lead to out-of-bound writes when a heap was initialize... Read more
Affected Products : linked-list-allocator- EPSS Score: %0.11
- Published: Sep. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-23853
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.... Read more
Affected Products : cpp6_firmware cpp7_firmware cpp7.3_firmware cpp4_firmware cpp13_firmware cpp6 cpp7 cpp7.3 cpp4 cpp13- EPSS Score: %0.31
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49433
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.... Read more
- EPSS Score: %0.28
- Published: Dec. 07, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-4982
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.... Read more
Affected Products : librenms- EPSS Score: %0.01
- Published: Sep. 15, 2023
- Modified: Nov. 21, 2024