Latest CVE Feed
-
9.8
CRITICALCVE-2023-7023
A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. Affected by this issue is some unknown functionality of the file general/vehicle/query/delete.php. The manipulation of the argument VU_ID leads to sql injection. The at... Read more
- Published: Dec. 21, 2023
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2023-50990
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.... Read more
- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51050
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.... Read more
Affected Products : s-cms- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51093
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.... Read more
- Published: Dec. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-33552
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.... Read more
Affected Products : xstore_core- Published: May. 17, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2023-51013
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanNetmask parameter’ of the setLanConfig interface of the cstecgi .cgi.... Read more
- Published: Dec. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-7109
A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack can be init... Read more
Affected Products : library_management_system- Published: Feb. 29, 2024
- Modified: Dec. 06, 2024
-
9.8
CRITICALCVE-2024-0182
A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/ of the component Admin Login. The manipulation of the argument username/password l... Read more
- Published: Jan. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0302
A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The manipulation leads to deserialization. The attack may be initiated remotely.... Read more
Affected Products : iparking- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51960
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2023-51961
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51958
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45688
An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locations.... Read more
Affected Products : ash- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-52027
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.... Read more
- Published: Jan. 11, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-0357
A vulnerability was found in coderd-repos Eva 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the file /system/traceLog/page of the component HTTP POST Request Handler. The manipulation of the argument property le... Read more
Affected Products : eva- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-52028
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.... Read more
- Published: Jan. 11, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-52311
PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system. ... Read more
Affected Products : paddlepaddle- Published: Jan. 03, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36693
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item.... Read more
Affected Products : ingredients_stock_management_system- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0784
A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/role/list. The manipulation of the argument dataScope leads to sql injection. It is possible to launch the attack r... Read more
Affected Products : octopus- Published: Jan. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10035
Improper Control of Generation of Code ('Code Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection.This issue affects CoslatV3: through 3.1069. NOTE: The vendor was contacted and it was learned that t... Read more
Affected Products : coslat- Published: Nov. 04, 2024
- Modified: Nov. 08, 2024