Latest CVE Feed
-
9.8
CRITICALCVE-2024-6096
In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.... Read more
Affected Products : telerik_reporting- Published: Jul. 24, 2024
- Modified: Apr. 25, 2025
-
5.9
MEDIUMCVE-2024-10846
The compose-go library component in versions v2.10-v2.4.0 allows an authorized user who sends malicious YAML payloads to cause the compose-go to consume excessive amount of Memory and CPU cycles while parsing YAML, such as used by Docker Compose from vers... Read more
Affected Products :- Published: Jan. 23, 2025
- Modified: Apr. 25, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2018-5733
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4.2.8,... Read more
- Published: Jan. 16, 2019
- Modified: Apr. 25, 2025
-
4.9
MEDIUMCVE-2022-45535
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
4.9
MEDIUMCVE-2022-45529
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-45331
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-45330
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.... Read more
Affected Products : aerocms- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44808
A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can proces... Read more
- Published: Nov. 22, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44252
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44251
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44250
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44249
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44139
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.... Read more
Affected Products : apartment_visitors_management_system- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
9.8
CRITICALCVE-2022-44120
dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.... Read more
Affected Products : dedecmsv6- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
4.8
MEDIUMCVE-2022-42985
The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).... Read more
Affected Products : scratch_login- Published: Nov. 17, 2022
- Modified: Apr. 25, 2025
-
7.2
HIGHCVE-2022-39833
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.... Read more
Affected Products : filecloud- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
6.3
MEDIUMCVE-2022-38753
This update resolves a multi-factor authentication bypass attack... Read more
Affected Products : netiq_advanced_authentication- Published: Nov. 28, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-38147
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
5.4
MEDIUMCVE-2022-38145
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.... Read more
- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025
-
7.5
HIGHCVE-2022-37772
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised... Read more
Affected Products : maarch_rm- Published: Nov. 23, 2022
- Modified: Apr. 25, 2025