Latest CVE Feed
-
7.8
HIGHCVE-2024-9287
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source v... Read more
Affected Products : python- Published: Oct. 22, 2024
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2024-6096
In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.... Read more
Affected Products : telerik_reporting- Published: Jul. 24, 2024
- Modified: Apr. 25, 2025
-
5.9
MEDIUMCVE-2024-10846
The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from vers... Read more
Affected Products :- Published: Jan. 23, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2018-5733
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8,... Read more
- Published: Jan. 16, 2019
- Modified: Apr. 25, 2025
-
4.9
MEDIUMCVE-2022-45535
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
4.9
MEDIUMCVE-2022-45529
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-45331
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-45330
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44808
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can proces... Read more
- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44252
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44251
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44250
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44249
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44139
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.... Read more
Affected Products : apartment_visitors_management_system- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44120
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.... Read more
Affected Products : dedecmsv6- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
4.8
MEDIUMCVE-2022-42985
The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).... Read more
Affected Products : scratch_login- Published: Nov. 17, 2022
- Modified: Apr. 25, 2025
-
7.2
HIGHCVE-2022-39833
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.... Read more
Affected Products : filecloud- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
6.3
MEDIUMCVE-2022-38753
This update resolves a multi-factor authentication bypass attack... Read more
Affected Products : netiq_advanced_authentication- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-38147
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-38145
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025