Search Results (30661 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-26339 2 Swftools, Swftools Project 2 Swftools, Swftools 2025-04-01 9.1 Critical
swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.
CVE-2025-26011 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setUsernamePassword.
CVE-2024-1783 1 Totolink 2 Lr1200gb, Lr1200gb Firmware 2025-04-01 9.8 Critical
A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi of the component Web Interface. The manipulation of the argument http_host leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-254574 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-25867 1 Codeastro 1 Membership Management System 2025-04-01 9.1 Critical
A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the membershipType and membershipAmount parameters in the add_type.php component.
CVE-2022-47767 1 Solar-log 18 Solar-log 1000, Solar-log 1000 Firmware, Solar-log 1000 Pm\+ and 15 more 2025-04-01 9.8 Critical
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included). This does not exist in SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base.
CVE-2022-25894 1 Uflo Project 1 Uflo 2025-04-01 9.8 Critical
All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.
CVE-2020-22452 1 Phpmyadmin 1 Phpmyadmin 2025-04-01 9.8 Critical
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
CVE-2022-40222 1 Siretta 2 Quartz-gold, Quartz-gold Firmware 2025-04-01 9.8 Critical
An OS command injection vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.
CVE-2023-22578 1 Sequelizejs 1 Sequelize 2025-04-01 10 Critical
Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.
CVE-2023-22579 1 Sequelizejs 1 Sequelize 2025-04-01 9.9 Critical
Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.
CVE-2022-41217 1 Hybridsoftware 1 Cloudflow 2025-04-01 9.8 Critical
Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.
CVE-2024-51065 1 Phpgurukul 1 Beauty Parlour Management System 2025-03-31 9.8 Critical
Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.
CVE-2024-51064 1 Phpgurukul 1 Teachers Record Management System 2025-03-31 9.8 Critical
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.
CVE-2024-51063 1 Phpgurukul 1 Teachers Record Management System 2025-03-31 9.1 Critical
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.
CVE-2022-44297 1 Sscms 1 Siteserver Cms 2025-03-31 9.8 Critical
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
CVE-2022-46967 1 Revenue Collection System Project 1 Revenue Collection System 2025-03-31 9.8 Critical
An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directory.
CVE-2024-28557 1 Mayurik 1 Php Task Management System 2025-03-31 9.8 Critical
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.
CVE-2024-28556 1 Mayurik 1 Php Task Management System 2025-03-31 9.8 Critical
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php.
CVE-2024-40477 1 Phpgurukul 1 Old Age Home Management System 2025-03-31 9.8 Critical
A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "email" parameter.
CVE-2023-22884 1 Apache 2 Airflow, Apache-airflow-providers-mysql 2025-03-31 9.8 Critical
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.