CVE Database

CVE-2017-20166CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.

CVE-2023-22903CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

api/views/user.py in LibrePhotos before e19e539 has incorrect access control.

CVE-2022-43514CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected component does not correctly validate the root path on folder related operations, allowing to modify files and folders outside the intended root directory. This could allow an unauthenticated remote attacker to execute file operations of files outside of the specified root folder. Chained with CVE-2022-43513 this could allow Remote Code Execution.

CVE-2022-3792CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating system: from unspecified before 5.0.13.

CVE-2022-4422CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Call Center System developed by Bulutses Information Technologies before version 3.0 has an unauthenticated Sql Injection vulnerability. This has been fixed in the version 3.0

CVE-2016-15017CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-21

A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects the function getUploadedFileList of the file Classes/Service/UploadFileService.php. The manipulation leads to pathname traversal. Upgrading to version 0.9.0 is able to address this issue. The patch is identified as b25d42a4981072321c1a363311d8ea2a4ac8763a. It is recommended to upgrade the affected component. VDB-217786 is the identifier assigned to this vulnerability.

CVE-2014-125073CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in mapoor voteapp. It has been rated as critical. Affected by this issue is the function create_poll/do_poll/show_poll/show_refresh of the file app.py. The manipulation leads to sql injection. The patch is identified as b290c21a0d8bcdbd55db860afd3cadec97388e72. It is recommended to apply a patch to fix this issue. VDB-217790 is the identifier assigned to this vulnerability.

CVE-2022-4337CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.

CVE-2022-4338CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.

CVE-2022-43389CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an unauthenticated attacker to execute some OS commands or to cause denial-of-service (DoS) conditions on a vulnerable device.

CVE-2022-48252CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter) OS Command Injection.

CVE-2022-48253CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the homedirs option is used.

CVE-2015-10036CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in kylebebak dronfelipe. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The patch is named 87405b74fe651892d79d0dff62ed17a7eaef6a60. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217951.

CVE-2015-10037CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, was found in ACI_Escola. This affects an unknown part. The manipulation leads to sql injection. The identifier of the patch is 34eed1f7b9295d1424912f79989d8aba5de41e9f. It is recommended to apply a patch to fix this issue. The identifier VDB-217965 was assigned to this vulnerability.

CVE-2022-47862CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.

CVE-2023-24162CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.

CVE-2022-34440CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-321

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges.

CVE-2022-34441CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-321

Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges.

CVE-2022-47865CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.

CVE-2022-47866CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.

CVE-2014-125074CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in Nayshlok Voyager. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file Voyager/src/models/DatabaseAccess.java. The manipulation leads to sql injection. The identifier of the patch is f1249f438cd8c39e7ef2f6c8f2ab76b239a02fae. It is recommended to apply a patch to fix this issue. The identifier VDB-218005 was assigned to this vulnerability.

CVE-2022-47864CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.

CVE-2017-20168CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in jfm-so piWallet. It has been rated as critical. Affected by this issue is some unknown functionality of the file api.php. The manipulation of the argument key leads to sql injection. The patch is identified as b420f8c4cbe7f06a34d1b05e90ee5cdfe0aa83bb. It is recommended to apply a patch to fix this issue. VDB-218006 is the identifier assigned to this vulnerability.

CVE-2022-47859CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.

CVE-2022-47860CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.

CVE-2022-47861CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.

CVE-2022-40615CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 236208.

CVE-2014-125075CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in gmail-servlet and classified as critical. This issue affects the function search of the file src/Model.java. The manipulation leads to sql injection. The identifier of the patch is 5d72753c2e95bb373aa86824939397dc25f679ea. It is recommended to apply a patch to fix this issue. The identifier VDB-218021 was assigned to this vulnerability.

CVE-2014-125076CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in NoxxieNl Criminals. It has been classified as critical. Affected is an unknown function of the file ingame/roulette.php. The manipulation of the argument gambleMoney leads to sql injection. The patch is identified as 0a60b31271d4cbf8babe4be993d2a3a1617f0897. It is recommended to apply a patch to fix this issue. VDB-218022 is the identifier assigned to this vulnerability.

CVE-2022-4498CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sent a crafted packet that causes a heap overflow. This can result in either a DoS (by crashing the httpd process) or an arbitrary code execution.

CVE-2022-4873CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.

CVE-2022-39184CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass.

CVE-2022-39185CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.

CVE-2022-3515CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.

CVE-2023-0243CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in TuziCMS 2.0.6. This affects the function index of the file App\Manage\Controller\ArticleController.class.php of the component Article Module. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-218151.

CVE-2023-0244CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical was found in TuziCMS 2.0.6. This vulnerability affects the function delall of the file \App\Manage\Controller\KefuController.class.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-218152.

CVE-2023-0245CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability, which was classified as critical, has been found in SourceCodester Online Flight Booking Management System. This issue affects some unknown processing of the file add_contestant.php. The manipulation of the argument add_contestant leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-218153 was assigned to this vulnerability.

CVE-2013-10011CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in aeharding classroom-engagement-system and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection. The attack may be launched remotely. The name of the patch is 096de5815c7b414e7339f3439522a446098fb73a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218156.

CVE-2022-46478CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.

CVE-2023-0256CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /fos/admin/ajax.php?action=login of the component Login Page. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-218184.

CVE-2023-0257CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fos/admin/index.php?page=menu of the component Menu Form. The manipulation of the argument Image with the input <?php system($_GET['c']); ?> leads to unrestricted upload. The attack can be launched remotely. The identifier VDB-218185 was assigned to this vulnerability.

CVE-2022-48149CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

CVE-2022-46471CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Health Care System v1.0 was discovered to contain a SQL injection vulnerability via the consulting_id parameter at /healthcare/Admin/consulting_detail.php.

CVE-2022-46502CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /student_enrollment/admin/login.php.

CVE-2023-23566CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

A 2-Step Verification problem in Axigen 10.3.3.52 allows an attacker to access a mailbox by bypassing 2-Step Verification when they try to add an account to any third-party webmail service (or add an account to Outlook or Gmail, etc.) with IMAP or POP3 without any verification code.

CVE-2022-21191CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

CVE-2023-0281CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability was found in SourceCodester Online Flight Booking Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file judge_panel.php. The manipulation of the argument subevent_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-218276.

CVE-2023-0283CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A vulnerability classified as critical has been found in SourceCodester Online Flight Booking Management System. This affects an unknown part of the file review_search.php of the component POST Parameter Handler. The manipulation of the argument txtsearch leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-218277 was assigned to this vulnerability.

CVE-2015-10041CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Dovgalyuk AIBattle. Affected is the function sendComments of the file site/procedures.php. The manipulation of the argument text leads to sql injection. The name of the patch is e3aa4d0900167641d41cbccf53909229f00381c9. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218304. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2022-46954CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_transaction.

← PreviousPage 472 / 7034Next →