CVE Database

CVE-2026-3395KEVCRITICALin_the_wild
CVSS 9.8
EPSS 0.05%
Priority 0
CWE CWE-74

A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 109.2 will fix this issue. This patch is called 08937a3c5d672a242d68f53e9fccf8a748820ef3. You should upgrade the affected component. The code maintainer was informed beforehand about the issues. He reacted very fast and highly professional.

CVE-2022-29007KEVCRITICALin_the_wild
CVSS 9.8
EPSS
Priority 0

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

CVE-2022-28895CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-28896CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-28901CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-28905CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parameter in /setting/setDeviceName.

CVE-2022-28909CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx parameter in /setting/setWebWlanIdx.

CVE-2022-28910CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicename parameter in /setting/setDeviceName.

CVE-2022-28911CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/CloudACMunualUpdate.

CVE-2022-28913CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUploadSetting.

CVE-2022-28915CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.

CVE-2022-29321CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.

CVE-2022-29322CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.

CVE-2022-29323CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.

CVE-2022-29324CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.

CVE-2022-29325CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.

CVE-2022-29326CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.

CVE-2022-29327CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.

CVE-2022-29328CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade.

CVE-2022-29329CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a heap overflow via the devicename parameter in /goform/setDeviceSettings.

CVE-2022-29009CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

CVE-2022-0947CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-665

A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration.

CVE-2022-23676CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.

CVE-2022-29391CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004200c8.

CVE-2022-29392CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418c24.

CVE-2022-29393CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004192cc.

CVE-2022-29394CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macAddress parameter in the function FUN_0041b448.

CVE-2022-29395CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the apcliKey parameter in the function FUN_0041bac4.

CVE-2022-29396CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_00418f10.

CVE-2022-29397CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004196c8.

CVE-2022-29398CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the File parameter in the function FUN_0041309c.

CVE-2022-29399CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the url parameter in the function FUN_00415bf0.

CVE-2022-20120CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Product: AndroidVersions: Android kernelAndroid ID: A-203213034References: N/A

CVE-2022-22012CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2026-9260CRITICALnone
CVSS 9.8
EPSS 0.23%
Priority 0
CWE CWE-321

Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

CVE-2026-9691CRITICALnone
CVSS 9.8
EPSS 0.48%
Priority 0
CWE CWE-502

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

CVE-2026-49781CRITICALnone
CVSS 9.8
EPSS 0.38%
Priority 0
CWE CWE-502

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

CVE-2026-49770CRITICALnone
CVSS 9.8
EPSS 0.38%
Priority 0
CWE CWE-502

Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.

CVE-2026-49768CRITICALnone
CVSS 9.8
EPSS 0.38%
Priority 0
CWE CWE-502

Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

CVE-2026-49765CRITICALnone
CVSS 9.8
EPSS 0.38%
Priority 0
CWE CWE-502

Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.

CVE-2026-49763CRITICALnone
CVSS 9.8
EPSS 0.38%
Priority 0
CWE CWE-502

Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

CVE-2026-49109CRITICALnone
CVSS 9.8
EPSS 0.38%
Priority 0
CWE CWE-502

Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.

CVE-2026-49104CRITICALnone
CVSS 9.8
EPSS 0.48%
Priority 0
CWE CWE-502

Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.

CVE-2017-6316KEVCRITICALin_the_wild
CVSS 9.8
EPSS 87.79%
Priority 70

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.

CVE-2022-29599CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-116

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

CVE-2026-39583CRITICALnone
CVSS 9.8
EPSS 0.36%
Priority 0
CWE CWE-266

Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.

CVE-2026-14894KEVCRITICALin_the_wild
CVSS 9.8
EPSS 0.52%
Priority 0
CWE CWE-434

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests.

CVE-2017-6526CRITICALpoc
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests).

CVE-2026-34901CRITICALnone
CVSS 9.8
EPSS 0.32%
Priority 0
CWE CWE-266

Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

CVE-2026-27053CRITICALnone
CVSS 9.8
EPSS 0.39%
Priority 0
CWE CWE-502

Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.

← PreviousPage 391 / 7034Next →