Latest CVE Feed
-
9.8
CRITICALCVE-2024-24332
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.... Read more
- Published: Jan. 30, 2024
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-7099
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file bwdates-report-result.php. The manipulation of the argument fromdate leads to... Read more
Affected Products : nipah_virus_testing_management_system- Published: Dec. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-7111
A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. Affected is an unknown function of the file index.php. The manipulation of the argument category leads to sql injection. It is possible to launch ... Read more
Affected Products : library_management_system- Published: Dec. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25019
IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. Attackers can make use of this weakness and upload malicious executable files into the system ... Read more
Affected Products : cognos_controller- Published: Dec. 03, 2024
- Modified: Dec. 11, 2024
-
9.8
CRITICALCVE-2022-3900
The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.... Read more
Affected Products : cooked- Published: Dec. 12, 2022
- Modified: Apr. 22, 2025
-
9.8
CRITICALCVE-2024-25400
Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, an... Read more
Affected Products : subrion- Published: Feb. 27, 2024
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2022-26096
Null pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.... Read more
- Published: Apr. 11, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-25995
An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.... Read more
- Published: Mar. 12, 2024
- Modified: Jan. 30, 2025
-
9.8
CRITICALCVE-2024-47311
Missing Authorization vulnerability in Kraft Plugins Wheel of Life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through 1.1.8.... Read more
Affected Products : wheel_of_life- Published: Nov. 01, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2021-25913
Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : set-or-get- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-21591
An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the ... Read more
Affected Products : junos- Published: Jan. 12, 2024
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2021-25941
Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.... Read more
Affected Products : deep-override- Published: May. 14, 2021
- Modified: Apr. 30, 2025
-
9.8
CRITICALCVE-2022-39365
Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to... Read more
Affected Products : pimcore- Published: Oct. 27, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-4826
SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisati... Read more
Affected Products :- Published: May. 16, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22319
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145. ... Read more
Affected Products : operational_decision_manager- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-27307
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to d... Read more
Affected Products :- Published: Mar. 06, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-27847
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.... Read more
Affected Products : xipblog- Published: Mar. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22779
Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.... Read more
Affected Products : serverrpexposer- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-22862
Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute arbitrary code via the JJPEG XL Parser.... Read more
Affected Products : ffmpeg- Published: Jan. 27, 2024
- Modified: Aug. 11, 2025
-
9.8
CRITICALCVE-2024-23054
An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).... Read more
Affected Products : plone_docker_official_image- Published: Feb. 05, 2024
- Modified: Nov. 21, 2024