Search Results (30648 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-40032 1 Simple Task Managing System Project 1 Simple Task Managing System 2025-03-18 9.8 Critical
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.
CVE-2024-31807 1 Totolink 2 Ex200, Ex200 Firmware 2025-03-18 9.8 Critical
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.
CVE-2024-43202 1 Apache 1 Dolphinscheduler 2025-03-18 9.8 Critical
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
CVE-2024-0709 1 Coolplugins 1 Cryptocurrency Widgets 2025-03-18 9.8 Critical
The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2023-24320 1 Axcora 1 Axcora 2025-03-18 9.8 Critical
An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.
CVE-2023-24114 1 Typecho 1 Typecho 2025-03-18 9.8 Critical
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
CVE-2023-24104 1 Ui 2 Unifi Dream Machine Pro, Unifi Dream Machine Pro Firmware 2025-03-18 9.8 Critical
Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.
CVE-2023-23453 1 Sick 4 Fx0-gent00000, Fx0-gent00000 Firmware, Fx0-gent00010 and 1 more 2025-03-18 9.8 Critical
Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
CVE-2023-23452 1 Sick 4 Fx0-gpnt00000, Fx0-gpnt00000 Firmware, Fx0-gpnt00010 and 1 more 2025-03-18 9.8 Critical
Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.
CVE-2022-3843 1 Wago 2 852-111\/000-001, 852-111\/000-001 Firmware 2025-03-18 9.1 Critical
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.
CVE-2024-23786 1 Sharp 4 Jh-rv11, Jh-rv11 Firmware, Jh-rvb1 and 1 more 2025-03-18 9.3 Critical
Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page of the affected product.
CVE-2024-25894 1 Churchcrm 1 Churchcrm 2025-03-17 9.8 Critical
ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.
CVE-2024-25893 1 Churchcrm 1 Churchcrm 2025-03-17 9.1 Critical
ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVE-2023-26093 1 Puzzle 1 Liima 2025-03-17 9.8 Critical
Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.
CVE-2023-26092 1 Puzzle 1 Liima 2025-03-17 9.8 Critical
Liima before 1.17.28 allows server-side template injection.
CVE-2022-45599 1 Aztech 2 Wmb250ac, Wmb250ac Firmware 2025-03-17 9.8 Critical
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.
CVE-2022-37938 1 Hpe 1 Serviceguard For Linux 2025-03-17 9.8 Critical
Unauthenticated server side request forgery in HPE Serviceguard Manager
CVE-2022-37937 1 Hpe 1 Serviceguard For Linux 2025-03-17 9.8 Critical
Pre-auth memory corruption in HPE Serviceguard
CVE-2022-37936 1 Hpe 1 Serviceguard For Linux 2025-03-17 9.8 Critical
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
CVE-2022-45564 1 Znfit 1 Home Improvement Erp Management System 2025-03-17 9.8 Critical
SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet.