Latest CVE Feed
-
9.8
CRITICALCVE-2020-27183
A RemoteFunctions endpoint with missing access control in konzept-ix publiXone before 2020.015 allows attackers to disclose sensitive user information, send arbitrary e-mails, escalate the privileges of arbitrary user accounts, and have unspecified other ... Read more
Affected Products : publixone- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-43693
vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.... Read more
Affected Products : vesta_control_panel- Published: Nov. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-0982
The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereby user input cmdline_len is copied into a fixed buffer b->buf without any bound checks. If the server connects with a malicious client,... Read more
Affected Products : accel-ppp- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-26512
CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq mess... Read more
- Published: Jul. 17, 2023
- Modified: Jun. 25, 2025
-
9.8
CRITICALCVE-2023-4677
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the... Read more
Affected Products : pandora_fms- Published: Nov. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-1082
A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The manipulation of the argument username/password with the input '||1=1# leads t... Read more
Affected Products : microfinance_management_system- Published: Mar. 29, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27105
A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical s... Read more
- Published: Apr. 25, 2023
- Modified: Feb. 03, 2025
-
9.8
CRITICALCVE-2023-23086
Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.... Read more
Affected Products : mojojson- Published: Feb. 03, 2023
- Modified: Mar. 26, 2025
-
9.8
CRITICALCVE-2023-27204
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.... Read more
Affected Products : best_pos_management_system- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-23331
Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.... Read more
Affected Products : xoffice- Published: Jan. 24, 2023
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2023-47458
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.... Read more
Affected Products : springblade- Published: Jan. 02, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2023-27583
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges. Version 3.1.3 h... Read more
Affected Products : panindex- Published: Mar. 13, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-48427
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the UMC se... Read more
Affected Products : sinec_ins- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-24040
Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.... Read more
Affected Products : parlai- Published: Sep. 10, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-24219
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.... Read more
Affected Products : luckyframeweb- Published: Feb. 17, 2023
- Modified: Mar. 18, 2025
-
9.8
CRITICALCVE-2021-34624
A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affect... Read more
Affected Products : profilepress- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-44348
SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class.php.... Read more
- Published: Dec. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-49750
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spoonthemes Couponis - Affiliate & Submitting Coupons WordPress Theme.This issue affects Couponis - Affiliate & Submitting Coupons WordPress Theme: from ... Read more
Affected Products : couponis- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-29215
In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. T... Read more
Affected Products : linkis- Published: Apr. 10, 2023
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2022-35846
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user v... Read more
Affected Products : fortitester- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024