Latest CVE Feed
-
9.8
CRITICALCVE-2024-0031
In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for... Read more
Affected Products : android- Published: Feb. 16, 2024
- Modified: Dec. 16, 2024
-
9.8
CRITICALCVE-2022-3735
A vulnerability was found in seccome Ehoney. It has been rated as critical. This issue affects some unknown processing of the file /api/public/signup. The manipulation leads to improper access controls. The identifier VDB-212417 was assigned to this vulne... Read more
Affected Products : ehoney- Published: Oct. 28, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-52200
Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup.This issue affects ARMember – Membership Plugin, Content ... Read more
Affected Products : armember- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-12954
A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. This affects an unknown part of the file /update_ach.php. The manipulation of the argument ach_certy leads to unrestricted upload. It is pos... Read more
Affected Products : portfolio_management_system_mca- Published: Dec. 26, 2024
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-0740
Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not require authentication. The fixed version is included in Eclipse IDE 2024-03 ... Read more
Affected Products : target_management- Published: Apr. 26, 2024
- Modified: Feb. 03, 2025
-
9.8
CRITICALCVE-2014-5014
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.... Read more
Affected Products : wordpress_flash_uploader- Published: Apr. 25, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-12936
A vulnerability, which was classified as critical, has been found in code-projects Simple Admin Panel 1.0. This issue affects some unknown processing of the file catDeleteController.php. The manipulation of the argument record leads to sql injection. The ... Read more
Affected Products : simple_admin_panel- Published: Dec. 26, 2024
- Modified: Apr. 17, 2025
-
9.8
CRITICALCVE-2024-0987
A vulnerability classified as critical has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected is an unknown function of the file /runtime/log. The manipulation leads to improper output neutralization for logs. The exploit has been disclos... Read more
Affected Products : kuerp- Published: Jan. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-25003
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE... Read more
- Published: Mar. 14, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0996
A vulnerability classified as critical has been found in Tenda i9 1.0.0.9(4122). This affects the function formSetCfm of the file /goform/setcfm of the component httpd. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is... Read more
- Published: Jan. 29, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10157
A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/password-recovery.php of the component Reset Your Password Page. The manipulation of the argument... Read more
Affected Products : boat_booking_system- Published: Oct. 19, 2024
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2021-22389
There is a Permission Control Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause certain codes to be executed.... Read more
- Published: Aug. 02, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-37611
Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.... Read more
Affected Products : gh-pages- Published: Oct. 12, 2022
- Modified: May. 15, 2025
-
9.8
CRITICALCVE-2022-37621
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.... Read more
Affected Products : browserify-shim- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2024-10369
A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /addcustcom.php. The manipulation of the argument refno leads to sql injection. The... Read more
Affected Products : sales_management_system- Published: Oct. 25, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2022-37801
Tenda AC1206 V15.03.06.23 was discovered to contain a stack overflow via the list parameter at the function formSetQosBand.... Read more
- Published: Aug. 25, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10619
A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /pda/reportshop/next_detail.php. The manipulation of the argument repid leads to sql injection. It is possible to launc... Read more
- Published: Nov. 01, 2024
- Modified: Nov. 04, 2024
-
9.8
CRITICALCVE-2022-37840
In TOTOLINK A860R V4.1.2cu.5182_B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability.... Read more
- Published: Sep. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-50985
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.... Read more
- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-40542
my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/role?offset.... Read more
Affected Products : my-springsecurity-plus- Published: Jul. 12, 2024
- Modified: Nov. 21, 2024