Latest CVE Feed
-
9.8
CRITICALCVE-2022-36179
Fusiondirectory 1.3 suffers from Improper Session Handling.... Read more
Affected Products : fusiondirectory- EPSS Score: %0.12
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
7.8
HIGHCVE-2022-35407
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. If the size of t... Read more
Affected Products : kernel- EPSS Score: %0.08
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
8.8
HIGHCVE-2022-33012
Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.... Read more
- EPSS Score: %0.54
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2021-3919
A potential security vulnerability has been identified in OMEN Gaming Hub and in HP Command Center which may allow escalation of privilege and/or denial of service. HP has released software updates to mitigate the potential vulnerability.... Read more
Affected Products : omen_gaming_hub command_center pavilion_gaming_tg01-2xxx envy_13t-bd100 envy_13z-ay100 envy_14-eb0xxx envy_14-eb1xxx envy_14t-eb100 envy_15-ep0xxx envy_15-ep1xxx +96 more products- EPSS Score: %0.83
- Published: Dec. 12, 2022
- Modified: Apr. 29, 2025
-
8.8
HIGHCVE-2021-29334
An issue was discovered in JIZHI CMS 1.9.4. There is a CSRF vulnerability that can add an admin account via index, /admin.php/Admin/adminadd.html... Read more
Affected Products : jizhicms- EPSS Score: %0.08
- Published: Nov. 23, 2022
- Modified: Apr. 29, 2025
-
6.5
MEDIUMCVE-2020-23593
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ' /mgm_log_cfg.asp.' The syst... Read more
- EPSS Score: %0.17
- Published: Nov. 23, 2022
- Modified: Apr. 29, 2025
-
8.8
HIGHCVE-2020-23592
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Reset ONU to Factory Default through ' /mgm_dev_reset.a... Read more
- EPSS Score: %0.56
- Published: Nov. 23, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2020-23591
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the... Read more
- EPSS Score: %0.40
- Published: Nov. 23, 2022
- Modified: Apr. 29, 2025
-
6.5
MEDIUMCVE-2020-23590
A vulnerability in Optilink OP-XT71000N Hardware version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated remote attacker to conduct a cross-site request forgery (CSRF) attack to change the Password for "WLAN SSID" through "wlwpa.asp".... Read more
- EPSS Score: %0.24
- Published: Nov. 23, 2022
- Modified: Apr. 29, 2025
-
6.5
MEDIUMCVE-2020-23589
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to cause a Denial of Service by Rebooting the router throu... Read more
- EPSS Score: %0.24
- Published: Nov. 23, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2025-28035
TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware a3100r a3000ru a830r a800r +2 more products- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-28036
TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware a3100r a3000ru a830r a800r +2 more products- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-28037
TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution vulnerability in the setDiagnosisCfg function through the ipDomain parameter.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-28038
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-28039
TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2022-45210
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.... Read more
Affected Products : jeecg_boot- EPSS Score: %0.06
- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
4.3
MEDIUMCVE-2022-45208
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.... Read more
Affected Products : jeecg_boot- EPSS Score: %0.06
- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-45207
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.... Read more
Affected Products : jeecg_boot- EPSS Score: %0.39
- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2022-45206
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.... Read more
Affected Products : jeecg_boot- EPSS Score: %0.08
- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025
-
5.3
MEDIUMCVE-2022-45205
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.... Read more
Affected Products : jeecg_boot- EPSS Score: %0.22
- Published: Nov. 25, 2022
- Modified: Apr. 29, 2025