CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 9.9 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors. |
| Exploit 1mo ago | 9.8 | Elemin allows remote attackers to upload and execute arbitrary PHP code via the Themify framework (before 1.2.2) wp-content/themes/elemin/themify/themify-ajax.php file. |
| Exploit 1mo ago | 9.8 | A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code. |
| 1mo ago | 10 | An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead to an out-of-bounds read. |
| 1mo ago | 9.8 | An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial number. The serial number can be retrieved by an unauthenticated user at /info.xml. |
| Exploit 1mo ago | 9.8 | Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some nonstandard build configurations. |
| Exploit 1mo ago | 9.8 | SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php. |
| Exploit 1mo ago | 9.8 | SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php. |
| Exploit 1mo ago | 9.8 | SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php. |
| Exploit 1mo ago | 9.8 | SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php. |
| Exploit 1mo ago | 9.8 | SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php. |
| Exploit 1mo ago | 9.8 | SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php. |
| Exploit 1mo ago | 9.8 | SQL Injection in ECShop 3.0 via the id parameter to admin/shophelp.php. |
| Exploit 1mo ago | 9.8 | SQL Injection in ECShop 2.7.6 via the goods_number parameter to flow.php. . |
| Exploit 1mo ago | 9.8 | SQL Injection in phpCMS 2008 sp4 via the genre parameter to yp/job.php. |
| Exploit 1mo ago | 9.8 | SQL Injection vulnerability in phpCMS 2007 SP6 build 0805 via the digg_mod parameter to digg_add.php. |
| Exploit 1mo ago | 9.8 | bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files). |
| Exploit 1mo ago | 9.8 | SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php. |
| Exploit 1mo ago | 9.8 | SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authentication and may be exploited by malicious users to obtain illegitimate access to the system. |
| 1mo ago | 9.8 | The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private networks using TCP Port 1947. While uninstalling, the uninstaller fails to close Port 1947. |
| Exploit 1mo ago | 9.1 | A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server. |
| Exploit 1mo ago | 9.8 | A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. |
| Exploit 1mo ago | 9.8 | tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-512 hash matching the SHA-512 hash of the message even if the signature was invalid. This issue is patched in version 7.0.3. As a workaround: In `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`. |
| Exploit 1mo ago | 9.8 | A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected. |
| 1mo ago | 9.8 | Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code. |
| 1mo ago | 9.8 | Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value. |
| 1mo ago | 9.8 | SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access that could allow an unauthenticated attacker to cause a denial-of-service condition, and/or execution of limited configuration modifications and/or execution of limited control commands on the SINAMICS Medium Voltage Products, Remote Access (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions). |
| Exploit 1mo ago | 9.8 | SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php. |
| 1mo ago | 9.8 | Product: AndroidVersions: Android SoCAndroid ID: A-175402462 |
| Exploit 1mo ago | 9.8 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were patched in version 2.1.59. As a workaround, ensure the connector is not exposed without authentication. |