Latest CVE Feed
-
6.7
MEDIUMCVE-2022-34438
Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malicious user with high privileges could potentially exploit this vulnerability, leading to full system compromise. This impacts compliance ... Read more
- EPSS Score: %0.05
- Published: Oct. 21, 2022
- Modified: May. 07, 2025
-
5.5
MEDIUMCVE-2022-2882
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1. A malicious maintainer could exfiltrate a GitHub integratio... Read more
Affected Products : gitlab- EPSS Score: %1.08
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2022-2826
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting from 12.10 before 12.10.7, all versions starting from 13.0 before 13.0.1. TODO... Read more
Affected Products : gitlab- EPSS Score: %0.08
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
6.5
MEDIUMCVE-2022-26884
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.... Read more
Affected Products : dolphinscheduler- EPSS Score: %0.40
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2021-42010
Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Please update to version 0.20.5-incubating which addresses this issue.... Read more
Affected Products : heron- EPSS Score: %0.26
- Published: Oct. 24, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2021-38737
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.... Read more
Affected Products : semcms- EPSS Score: %0.34
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2021-38736
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.... Read more
Affected Products : semcms- EPSS Score: %0.34
- Published: Oct. 28, 2022
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2025-3168
A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php. The manipulation of the argument editid leads to sql i... Read more
Affected Products : time_table_generator_system- Published: Apr. 03, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3352
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-scdetails.php. The manipulation of the argument contnum leads to sql inject... Read more
Affected Products : old_age_home_management_system- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-20348
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning... Read more
- Published: Apr. 03, 2024
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2025-3370
A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. It is possible t... Read more
Affected Products : men_salon_management_system- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
8.0
HIGHCVE-2024-48629
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the IPAddress parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands ... Read more
- Published: Oct. 17, 2024
- Modified: May. 07, 2025
-
8.0
HIGHCVE-2024-48630
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a craft... Read more
- Published: Oct. 17, 2024
- Modified: May. 07, 2025
-
9.8
CRITICALCVE-2024-48168
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.... Read more
- Published: Oct. 14, 2024
- Modified: May. 07, 2025
-
8.0
HIGHCVE-2024-48632
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attac... Read more
- Published: Oct. 17, 2024
- Modified: May. 07, 2025
-
8.0
HIGHCVE-2024-48631
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a craft... Read more
- Published: Oct. 17, 2024
- Modified: May. 07, 2025
-
8.0
HIGHCVE-2024-48633
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vul... Read more
- Published: Oct. 17, 2024
- Modified: May. 07, 2025
-
8.0
HIGHCVE-2024-48634
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute arbitrary OS commands via a crafte... Read more
- Published: Oct. 17, 2024
- Modified: May. 07, 2025
-
8.0
HIGHCVE-2024-48635
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a cr... Read more
- Published: Oct. 17, 2024
- Modified: May. 07, 2025
-
8.0
HIGHCVE-2024-48637
D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a cr... Read more
- Published: Oct. 17, 2024
- Modified: May. 07, 2025