Latest CVE Feed
-
9.8
CRITICALCVE-2023-6943
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) ver... Read more
Affected Products : gx_works3 mc_works64 gx_works2 melsoft_navigator mt_works2 ezsocket fr_configurator2 mx_component got1000 got2000- Published: Jan. 30, 2024
- Modified: Feb. 13, 2025
-
9.8
CRITICALCVE-2021-24361
In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection issues.... Read more
Affected Products : location_manager- Published: Jun. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-7023
A vulnerability was found in Tongda OA 2017 up to 11.9. It has been rated as critical. Affected by this issue is some unknown functionality of the file general/vehicle/query/delete.php. The manipulation of the argument VU_ID leads to sql injection. The at... Read more
- Published: Dec. 21, 2023
- Modified: Mar. 19, 2025
-
9.8
CRITICALCVE-2023-50990
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.... Read more
- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51050
S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.... Read more
Affected Products : s-cms- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51093
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.... Read more
- Published: Dec. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-33552
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.... Read more
Affected Products : xstore_core- Published: May. 17, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2023-51013
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanNetmask parameter’ of the setLanConfig interface of the cstecgi .cgi.... Read more
- Published: Dec. 22, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-7109
A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack can be init... Read more
Affected Products : library_management_system- Published: Feb. 29, 2024
- Modified: Dec. 06, 2024
-
9.8
CRITICALCVE-2024-0182
A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/ of the component Admin Login. The manipulation of the argument username/password l... Read more
- Published: Jan. 01, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0302
A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The manipulation leads to deserialization. The attack may be initiated remotely.... Read more
Affected Products : iparking- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51960
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Jun. 16, 2025
-
9.8
CRITICALCVE-2023-51961
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-51958
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.... Read more
- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-45688
An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locations.... Read more
Affected Products : ash- Published: Dec. 27, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-52027
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.... Read more
- Published: Jan. 11, 2024
- Modified: Jun. 17, 2025
-
9.8
CRITICALCVE-2024-0357
A vulnerability was found in coderd-repos Eva 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the file /system/traceLog/page of the component HTTP POST Request Handler. The manipulation of the argument property le... Read more
Affected Products : eva- Published: Jan. 10, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-52028
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg function.... Read more
- Published: Jan. 11, 2024
- Modified: Jun. 20, 2025
-
9.8
CRITICALCVE-2023-52311
PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system. ... Read more
Affected Products : paddlepaddle- Published: Jan. 03, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-36693
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item.... Read more
Affected Products : ingredients_stock_management_system- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024