CVE Vulnerabilities
CVE vulnerability database enriched with CISA KEV and NVD data
| CVE ID | CVSS | Severity | KEV | Sightings |
|---|---|---|---|---|
| CVE-2024-40472 Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php." | 9.8 | CRITICAL | — | 0 |
| CVE-2024-8456 Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and sys... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-35515 Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-8607 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection.This issue affects ValeApp: before v2.0.0. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-8643 Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking.This issue affects ValeApp: before v2.0.0. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-6981 OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-8310 OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges. | 9.8 | CRITICAL | — | 0 |
| CVE-2026-22562 A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device firmware to write files on the system that could be used for a remote code exec... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29731 SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-44902 A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-34048 vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write po... | 9.8 | CRITICAL | KEV | 0 |
| CVE-2024-44410 D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29730 SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29729 SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29728 SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29727 SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29726 SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29725 SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29724 SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29723 SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-45435 Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-45233 An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, res... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-38989 izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via ... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-45508 HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-45488 One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). Th... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-45522 Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-34195 TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restrictio... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-42905 Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-1316 Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device | 9.8 | CRITICAL | KEV | 0 |
| CVE-2024-6671 In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encr... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-41370 Organizr v1.90 was discovered to contain a SQL injection vulnerability via chat/setlike.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-23897 Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, ... | 9.8 | CRITICAL | KEV | 0 |
| CVE-2024-41369 RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php | 9.8 | CRITICAL | — | 0 |
| CVE-2023-7249 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Service... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-41368 RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php | 9.8 | CRITICAL | — | 0 |
| CVE-2024-41367 RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php | 9.8 | CRITICAL | — | 0 |
| CVE-2024-41366 RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php | 9.8 | CRITICAL | — | 0 |
| CVE-2024-41364 RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php | 9.8 | CRITICAL | — | 0 |
| CVE-2024-41361 RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php | 9.8 | CRITICAL | — | 0 |
| CVE-2024-42466 Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-0785 The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to una... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-20170 Product: AndroidVersions: Android kernelAndroid ID: A-209421931References: N/A | 9.8 | CRITICAL | — | 0 |
| CVE-2022-32352 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-42675 Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP file and obtain remote code execution. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-27668 Depending on the configuration of the route permission table in file 'saprouttab', it is possible for an unauthenticated attacker to execute SAProuter administration commands in SAP NetWeaver and ABAP... | 9.8 | CRITICAL | — | 0 |
| CVE-2021-40386 Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code. | 9.8 | CRITICAL | — | 0 |
| CVE-2021-46560 The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-26651 An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL qu... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-20171 Product: AndroidVersions: Android kernelAndroid ID: A-215565667References: N/A | 9.8 | CRITICAL | — | 0 |
| CVE-2022-32337 Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=. | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.