Latest CVE Feed
-
9.8
CRITICALCVE-2024-6047
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.... Read more
Affected Products : gv-dsp_lpr_firmware gv-dsp_lpr gvlx_4_firmware gvlx_4 gv_ipcamd_gv_bx130_firmware gv_ipcamd_gv_bx130 gv_ipcamd_gv_bx1500_firmware gv_ipcamd_gv_bx1500 gv_ipcamd_gv_cb220_firmware gv_ipcamd_gv_cb220 +27 more products- Actively Exploited
- Published: Jun. 17, 2024
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2024-11120
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploite... Read more
Affected Products : gv-vs12_firmware gv-vs12 gv-vs11_firmware gv-vs11 gv-dsp_lpr_firmware gv-dsp_lpr gvlx_4_firmware gvlx_4- Actively Exploited
- Published: Nov. 15, 2024
- Modified: May. 09, 2025
-
6.1
MEDIUMCVE-2025-45388
Wagtail CMS 6.4.1 is vulnerable to a Stored Cross-Site Scripting (XSS) in the document upload functionality. Attackers can inject malicious code inside a PDF file. When a user clicks the document in the CMS interface, the payload executes. NOTE: this is d... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2022-43415
Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : repo- EPSS Score: %0.26
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.5
MEDIUMCVE-2022-43045
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_sffield at /scene_manager/scene_dump.c.... Read more
Affected Products : gpac- EPSS Score: %0.04
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.5
MEDIUMCVE-2022-43044
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_get_meta_item_info at /isomedia/meta.c.... Read more
Affected Products : gpac- EPSS Score: %0.03
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
5.5
MEDIUMCVE-2022-43043
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTimeOffset at /bifs/field_decode.c.... Read more
Affected Products : gpac- EPSS Score: %0.03
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
7.8
HIGHCVE-2022-43042
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at isomedia/isom_intern.c.... Read more
Affected Products : gpac- EPSS Score: %0.07
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
7.8
HIGHCVE-2022-43040
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump_start_ex at /isomedia/box_funcs.c.... Read more
Affected Products : gpac- EPSS Score: %0.05
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-43026
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.... Read more
- EPSS Score: %0.17
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-43025
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.... Read more
- EPSS Score: %0.17
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-43024
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.... Read more
- EPSS Score: %0.17
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
8.8
HIGHCVE-2024-39841
A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
Affected Products : centreon_web- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
9.1
CRITICALCVE-2024-33854
A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
Affected Products : centreon_web- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
9.1
CRITICALCVE-2024-33853
A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
Affected Products : centreon_web- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
9.1
CRITICALCVE-2024-33852
A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
Affected Products : centreon_web- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2024-32501
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
8.0
HIGHCVE-2024-52739
D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.... Read more
- Published: Nov. 20, 2024
- Modified: May. 09, 2025
-
9.9
CRITICALCVE-2024-51478
YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.... Read more
Affected Products : yeswiki- Published: Oct. 31, 2024
- Modified: May. 09, 2025
-
7.6
HIGHCVE-2025-24017
YesWiki is a wiki system written in PHP. Versions up to and including 4.4.5 are vulnerable to any end-user crafting a DOM based XSS on all of YesWiki's pages which is triggered when a user clicks on a malicious link. The vulnerability makes use of the sea... Read more
Affected Products : yeswiki- Published: Jan. 21, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting