Vulnerabilidades CVE
Base de dados CVE enriquecida com CISA KEV e NVD
| CVE ID | CVSS | Severidade | KEV | Avistamentos |
|---|---|---|---|---|
| CVE-2025-30727 Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows ... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-32011 KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-43135 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-43999 An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-31866 Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES.... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44000 An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-31022 An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44003 An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44004 An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a ... | 9.8 | CRITICAL | — | 0 |
| CVE-2017-12652 libpng before 1.6.32 does not properly check the length of chunks against the user limit. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-40625 Unrestricted file upload in TCMAN's GIM v11. This vulnerability allows an unauthenticated attacker to upload any file within the server, even a malicious file to obtain a Remote Code Execution (RCE). | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44006 An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-3918 The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration hand... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-40881 SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php | 9.8 | CRITICAL | — | 0 |
| CVE-2019-12900 BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-42245 Dreamer CMS 4.0.01 is vulnerable to SQL Injection. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-30849 Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-45474 drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-29432 Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-48581 File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-24543 Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or run arbitrary code via craf... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44204 D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-43138 Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-2332 The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.13 via deserialization of untrusted input in ... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-26008 In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-31002 Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51518 Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, this could be leverag... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-24112 xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-26007 Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-44001 An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-26006 Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-49959 In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root pri... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-25730 Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only about one million po... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-26005 Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-36784 Elsight – Elsight Halo Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-38165 Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-29046 Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the GAPSMinute3 key value | 9.8 | CRITICAL | — | 0 |
| CVE-2024-46054 OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files. | 9.8 | CRITICAL | — | 0 |
| CVE-2025-4524 The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. T... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-55964 An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacke... | 9.8 | CRITICAL | — | 0 |
| CVE-2022-37897 There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UD... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-24163 SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-55028 A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-50919 Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution | 9.8 | CRITICAL | — | 0 |
| CVE-2022-20388 Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323 | 9.8 | CRITICAL | — | 0 |
| CVE-2023-28500 A Java insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier allows unauthenticated remote attackers to gain operating system code execution by submitting specially cr... | 9.8 | CRITICAL | — | 0 |
| CVE-2025-28399 An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-24468 Broken access control in Advanced Authentication versions prior to 6.4.1.1 and 6.3.7.2 | 9.8 | CRITICAL | — | 0 |
| CVE-2023-26802 An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted reque... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-22852 D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted pa... | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.