CVE Database

CVE-2022-29316CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Complete Online Job Search System v1.0 was discovered to contain a SQL injection vulnerability via /eris/index.php?q=result&searchfor=advancesearch.

CVE-2022-28575CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payload

CVE-2022-28577CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

CVE-2022-28578CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

CVE-2016-10175CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-200

The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions.

CVE-2022-29317CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.

CVE-2016-10174KEVCRITICALin_the_wild
CVSS 9.8
EPSS 89.86%
Priority 70

The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

CVE-2004-2061CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL.

CVE-2025-30406KEVCRITICALin_the_wild
CVSS 9.8
EPSS 87.94%
Priority 70

Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.

CVE-2026-8206KEVCRITICALin_the_wild
CVSS 9.8
EPSS 0.12%
Priority 0
CWE CWE-269

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.

CVE-2022-28579CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

CVE-2026-7515KEVCRITICALin_the_wild
CVSS 9.8
EPSS 0.89%
Priority 0

The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

CVE-2022-28580CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

CVE-2022-29656CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.

CVE-2022-28581CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

CVE-2022-28582CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

CVE-2022-28583CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

CVE-2022-28584CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

CVE-2022-27360CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

CVE-2022-27411CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Main" function.

CVE-2022-29535CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.

CVE-2015-9266CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.

CVE-2022-29161CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-327

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 certificates signed by default using SHA1 with RSA, which is not considered safe anymore for use in certificate signatures, due to the risk of collisions with SHA1. The problem has been patched in XWiki version 13.10.6, 14.3.1 and 14.4-rc-1. Since then, the Crypto API will generate X509 certificates signed by default using SHA256 with RSA. Administrators are advised to upgrade their XWiki installation to one of the patched versions. If the upgrade is not possible, it is possible to patch the module xwiki-platform-crypto in a local installation by applying the change exposed in 26728f3 and re-compiling the module.

CVE-2026-48907KEVCRITICALin_the_wild
CVSS 9.8
EPSS 0.11%
Priority 0
CWE CWE-284

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

CVE-2007-3010KEVCRITICALin_the_wild
CVSS 9.8
EPSS 94.01%
Priority 70

masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.

CVE-2022-29006CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.

CVE-2018-11511CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.

CVE-2020-19213CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.

CVE-2018-11510CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.

CVE-2022-28163CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.

CVE-2019-12254CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.

CVE-2021-27762CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses

CVE-2018-11509CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.

CVE-2022-29423CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-264

Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.

CVE-2021-23592CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.

CVE-2021-23792CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered.

CVE-2022-29180CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delete anything on the server. This has been patched and is available in release [v0.12.1](https://github.com/charmbracelet/charm/releases/tag/v0.12.1). We recommend that all users running self-hosted `charm` instances update immediately. This vulnerability was found in-house and we haven't been notified of any potential exploiters. ### Additional notes * Encrypted user data uploaded to the Charm server is safe as Charm servers cannot decrypt user data. This includes filenames, paths, and all key-value data. * Users running the official Charm [Docker images](https://github.com/charmbracelet/charm/blob/main/docker.md) are at minimal risk because the exploit is limited to the containerized filesystem.

CVE-2026-45247KEVCRITICALin_the_wild
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.

CVE-2022-28470CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.

CVE-2020-23426CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-352

zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.

CVE-2026-41176KEVCRITICALin_the_wild
CVSS 9.8
EPSS 2.79%
Priority 0
CWE CWE-306

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `AuthRequired: true` on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitive administrative functionality, including configuration and operational RC methods. Version 1.73.5 patches the issue.

CVE-2022-0814CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

CVE-2022-0817CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVE-2022-0836CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL statements via an AJAX action, leading to SQL Injections exploitable by unauthenticated users

CVE-2022-1013CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

CVE-2022-28738CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.

CVE-2022-30335CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.

CVE-2021-43094CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.

CVE-2022-28110CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.

CVE-2022-29591CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.

← PreviousPage 390 / 7034Next →