CVE Database

CVE-2022-0785KEVCRITICALin_the_wild
CVSS 9.8
EPSS 70.35%
Priority 0

The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

CVE-2017-11357KEVCRITICALin_the_wild
CVSS 9.8
EPSS 93.84%
Priority 70

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

CVE-2017-11317KEVCRITICALin_the_wild
CVSS 9.8
EPSS 91.98%
Priority 70

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

CVE-2015-2147CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.

CVE-2026-51808CRITICALnone
CVSS 9.8
EPSS 0.48%
Priority 0

Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before allows an attacker to execute arbitrary code via the openhtj2k_decoder_impl::invoke, invoke_line_based, invoke_line_based_stream, and invoke_line_based_predecoded function in source/core/interface/decoder.cpp

CVE-2022-28082CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.

CVE-2022-28512CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.

CVE-2022-28568CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.

CVE-2022-29347CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

CVE-2022-28557CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution

CVE-2021-42235CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.

CVE-2017-17651CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.

CVE-2022-29155CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping.

CVE-2022-30284CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-88

In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted network, and thus the CVSS score corresponds to an unrealistic use case. None of the NmapProcess documentation implies that this is an expected use case

CVE-2021-42654CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.

CVE-2022-28890CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.

CVE-2021-41739CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.

CVE-2026-30618CRITICALnone
CVSS 9.8
EPSS 1.67%
Priority 0

xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and parameters, resulting in execution of arbitrary commands on the server. Successful exploitation allows arbitrary command execution within the context of the Fay service.

CVE-2021-42242CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.

CVE-2022-28461CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.

CVE-2021-38423CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-131

All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buffer overflow.

CVE-2022-30454CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product.

CVE-2021-38435CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-131

RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocating the buffer, which may result in a buffer overflow.

CVE-2021-38439CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or remotely execute arbitrary code.

CVE-2022-30455CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id.

CVE-2021-38441CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-123

Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.

CVE-2021-38443CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-228

Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.

CVE-2021-38445CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-130

OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associated data, which may allow an attacker to remotely execute arbitrary code.

CVE-2022-30461CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id

CVE-2026-9810CRITICALnone
CVSS 9.8
EPSS 0.28%
Priority 0

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and role escalation.

CVE-2021-44055CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 ( 2022/02/16 ) and later

CVE-2021-44056CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 and later Video Station 5.3.13 and later Video Station 5.1.8 and later

CVE-2021-44057CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 ( 2022/02/11 ) and later Photo Station 5.4.13 ( 2022/02/11 ) and later

CVE-2022-27588CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later

CVE-2022-28120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server.

CVE-2022-28530CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.

CVE-2022-28533CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.

CVE-2022-28606CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.

CVE-2022-1556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

CVE-2026-53384CRITICALnone
CVSS 9.8
EPSS 0.17%
Priority 0

In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails dw8250_probe() registers the 8250 port via serial8250_register_8250_port() and then, if the device has a clock, registers a clock notifier. If clk_notifier_register() fails, probe returns the error but leaves the 8250 port registered. The matching serial8250_unregister_port() lives in dw8250_remove(), which is not called when probe fails, so the port slot stays occupied until the device is rebound or the system is rebooted. The devm-allocated driver data is freed while the port still references it (via the saved private_data and serial_in/serial_out callbacks), so any access to that port slot before a rebind is a use-after-free hazard. Unregister the port on the clk_notifier_register() error path.

CVE-2025-59374KEVCRITICALin_the_wild
CVSS 9.8
EPSS 31.79%
Priority 70

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.

CVE-2017-15970CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.

CVE-2021-29936CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-908

An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via the FromIterator implementation for Vector and Matrix.

CVE-2017-15081CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.

CVE-2018-5211CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.

CVE-2022-29502CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.

CVE-2021-29937CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-908

An issue was discovered in the telemetry crate through 2021-02-17 for Rust. There is a drop of uninitialized memory if a value.clone() call panics within misc::vec_with_size().

CVE-2021-29940CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in the through crate through 2021-02-18 for Rust. There is a double free (in through and through_and) upon a panic of the map function.

CVE-2014-7169KEVCRITICALin_the_wild
CVSS 9.8
EPSS 90.11%
Priority 70

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

CVE-2022-29592CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).

← PreviousPage 389 / 7034Next →