CVE-2024-49242 | CRITICAL | 10.0 | 0.00511 | 40.18 | No | No | 2024-10-16 | 2026-04-29 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a Web Shell to a Web S…Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through <= 3.0.5. |
CVE-2018-1469 | CRITICAL | 9.8 | 0.02788 | 40.18 | No | No | 2018-04-04 | 2024-09-16 | euvd | IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially …IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605. |
CVE-2026-35431 | CRITICAL | 10.0 | 0.00511 | 40.18 | No | No | 2026-04-23 | 2026-08-14 | euvd | Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a n…Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. |
CVE-2025-64420 | CRITICAL | 10.0 | 0.00504 | 40.18 | No | No | 2026-01-05 | 2026-01-05 | euvd | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and includi…Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh to the server and authenticate as root user, using the private key. As of time of publication, it is unclear if a patch is available. |
CVE-2025-32440 | CRITICAL | 10.0 | 0.00527 | 40.18 | No | No | 2025-05-27 | 2025-05-28 | euvd | NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanis…NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings without authentication. An attacker can trigger sensitive functions within util.php by sending crafted requests to /index.php. This issue has been patched in version 25.4.14. |
CVE-2023-2766 | MEDIUM | 5.3 | 0.54232 | 40.18 | No | No | 2023-05-17 | 2024-08-02 | euvd | A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/b…A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |
CVE-2022-24664 | CRITICAL | 9.9 | 0.0165 | 40.18 | No | No | 2022-02-16 | 2025-01-31 | euvd | PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by a…PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts. |
CVE-2018-3832 | CRITICAL | 9.9 | 0.01656 | 40.18 | No | No | 2018-08-23 | 2024-09-17 | euvd | An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows for uploading arbit…An exploitable firmware update vulnerability exists in Insteon Hub running firmware version 1013. The HTTP server allows for uploading arbitrary MPFS binaries that could be modified to enable access to hidden resources which allow for uploading unsigned firmware images to the device. To trigger this vulnerability, an attacker can upload an MPFS binary via the '/mpfsupload' HTTP form and later on upload the firmware via a POST request to 'firmware.htm'. |
CVE-2020-7706 | CRITICAL | 9.8 | 0.028 | 40.18 | No | No | 2020-08-18 | 2024-09-16 | euvd | The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie. |
CVE-2024-50495 | CRITICAL | 10.0 | 0.00515 | 40.18 | No | No | 2024-10-28 | 2026-05-11 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in nunomorgadinho Plugin Propagator wp-propagator allows Upload a Web Shell to…Unrestricted Upload of File with Dangerous Type vulnerability in nunomorgadinho Plugin Propagator wp-propagator allows Upload a Web Shell to a Web Server.This issue affects Plugin Propagator: from n/a through <= 0.1. |
CVE-2024-51790 | CRITICAL | 10.0 | 0.00527 | 40.18 | No | No | 2024-11-11 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in HB WEBSOL HB AUDIO GALLERY hb-audio-gallery allows Upload a Web Shell to a …Unrestricted Upload of File with Dangerous Type vulnerability in HB WEBSOL HB AUDIO GALLERY hb-audio-gallery allows Upload a Web Shell to a Web Server.This issue affects HB AUDIO GALLERY: from n/a through <= 3.0. |
CVE-2026-31957 | CRITICAL | 10.0 | 0.00501 | 40.18 | No | No | 2026-03-11 | 2026-03-12 | euvd | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed witho…Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentication is not tenant-scoped. In this mode, Himmelblau can accept authentication attempts for arbitrary Entra ID domains by dynamically registering providers at runtime. This behavior is intended for initial/local bootstrap scenarios, but it can create risk in remote authentication environments. This vulnerability is fixed in 3.1.0. |
CVE-2025-50002 | CRITICAL | 10.0 | 0.00507 | 40.18 | No | No | 2026-01-22 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue…Unrestricted Upload of File with Dangerous Type vulnerability in Farost Energia energia allows Upload a Web Shell to a Web Server.This issue affects Energia: from n/a through <= 1.1.2. |
CVE-2024-50523 | CRITICAL | 10.0 | 0.00515 | 40.18 | No | No | 2024-11-04 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allpost-contactform allows Upload a …Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allpost-contactform allows Upload a Web Shell to a Web Server.This issue affects All Post Contact Form: from n/a through <= 1.8.2. |
CVE-2024-52476 | CRITICAL | 10.0 | 0.00527 | 40.18 | No | No | 2024-12-02 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell …Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell to a Web Server.This issue affects Fediverse Embeds: from n/a through <= 1.5.3. |
CVE-2024-35746 | CRITICAL | 10.0 | 0.00511 | 40.18 | No | No | 2024-06-10 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection.This issue affects …Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection.This issue affects BuddyPress Cover: from n/a through 2.1.4.2. |
CVE-2021-32590 | CRITICAL | 9.9 | 0.01655 | 40.18 | No | No | 2021-08-04 | 2024-10-25 | euvd | Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 throug…Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbitrary commands on the underlying SQL database via specifically crafted HTTP requests. |
CVE-2026-1699 | CRITICAL | 10.0 | 0.00504 | 40.18 | No | No | 2026-01-30 | 2026-02-02 | euvd | In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while ch…In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). An attacker could exfiltrate secrets, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and push malicious code to the repository. |
CVE-2020-12775 | CRITICAL | 9.8 | 0.02801 | 40.18 | No | No | 2022-03-01 | 2024-09-16 | euvd | Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthent…Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt system or terminate service. |
CVE-2026-46595 | CRITICAL | 10.0 | 0.00503 | 40.18 | No | Yes | 2026-05-22 | 2026-08-14 | euvd, nvd, packetstorm | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed othe…Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped. |
CVE-2026-33591 | CRITICAL | 10.0 | 0.00523 | 40.18 | No | No | 2026-08-03 | 2026-08-03 | euvd, nvd | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass
security restriction using a s…A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass
security restriction using a specially crafted packet and retrieve a valid
session token for the targeted account. |
CVE-2025-59360 | CRITICAL | 9.8 | 0.02814 | 40.18 | No | Yes | 2025-09-15 | 2025-09-15 | euvd, packetstorm | The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allow…The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster. |
CVE-2025-57870 | CRITICAL | 10.0 | 0.00506 | 40.18 | No | No | 2025-10-22 | 2026-02-26 | euvd | A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability…A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase. |
CVE-2026-33494 | CRITICAL | 10.0 | 0.00519 | 40.18 | No | Yes | 2026-03-26 | 2026-03-27 | euvd, packetstorm | ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rul…ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. An attacker can craft a URL containing path traversal sequences (e.g. `/public/../admin/secrets`) that resolves to a protected path after normalization, but is matched against a permissive rule because the raw, un-normalized path is used during rule evaluation. Version 26.2.0 contains a patch. |
CVE-2020-27134 | CRITICAL | 9.9 | 0.01647 | 40.18 | No | No | 2020-12-11 | 2024-11-13 | euvd | Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute a…Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information. For more information about these vulnerabilities, see the Details section of this advisory. |
CVE-2024-50494 | CRITICAL | 10.0 | 0.00511 | 40.18 | No | No | 2024-10-29 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-sudan-payment-gateway al…Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-sudan-payment-gateway allows Upload a Web Shell to a Web Server.This issue affects Sudan Payment Gateway for WooCommerce: from n/a through <= 1.2.2. |
CVE-2024-49327 | CRITICAL | 10.0 | 0.00516 | 40.18 | No | No | 2024-10-20 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows Upload a Web Shell t…Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows Upload a Web Shell to a Web Server.This issue affects Woostagram Connect: from n/a through <= 1.0.2. |
CVE-2024-34990 | CRITICAL | 10.0 | 0.00514 | 40.18 | No | No | 2024-06-19 | 2024-08-02 | euvd | In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer ca…In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontController::submitTicket()` and `HelpdeskHelpdeskModuleFrontController::replyTicket()` allow upload of .php files on a predictable path for connected customers. |
CVE-2026-27574 | CRITICAL | 10.0 | 0.00505 | 40.18 | No | No | 2026-02-21 | 2026-02-24 | euvd | OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses No…OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape via a well-known one-liner that grants full access to the underlying process. Because the probe runs with host networking and holds all cluster credentials (ONEUPTIME_SECRET, DATABASE_PASSWORD, REDIS_PASSWORD, CLICKHOUSE_PASSWORD) in its environment variables, and monitor creation is available to the lowest role (ProjectMember) with open registration enabled by default, any anonymous user can achieve full cluster compromise in about 30 seconds. This issue has been fixed in version 10.0.5. |
CVE-2023-1437 | CRITICAL | 9.8 | 0.02798 | 40.18 | No | No | 2023-08-02 | 2024-08-02 | euvd | All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent coul…All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite files. |
CVE-2026-49200 | CRITICAL | 10.0 | 0.00518 | 40.18 | No | No | 2026-05-29 | 2026-05-29 | euvd, nvd | The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login …The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access. |
CVE-2024-49314 | CRITICAL | 10.0 | 0.00515 | 40.18 | No | No | 2024-10-17 | 2026-05-11 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in jiangqie JiangQie Free Mini Program jiangqie-free-mini-program allows Uploa…Unrestricted Upload of File with Dangerous Type vulnerability in jiangqie JiangQie Free Mini Program jiangqie-free-mini-program allows Upload a Web Shell to a Web Server.This issue affects JiangQie Free Mini Program: from n/a through <= 2.5.2. |
CVE-2024-50531 | CRITICAL | 10.0 | 0.00511 | 40.18 | No | No | 2024-11-04 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upl…Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through <= 6.2.4. |
CVE-2026-14894 | CRITICAL | 9.8 | 0.02803 | 40.18 | No | Yes | 2026-07-10 | 2026-07-10 | euvd, packetstorm | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including,…The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests. |
CVE-2026-41228 | CRITICAL | 10.0 | 0.00524 | 40.18 | No | No | 2026-04-23 | 2026-04-23 | euvd | Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.upda…Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set `def_language` to a path traversal payload (e.g., `../../../../../var/customers/webs/customer1/evil`), which is stored in the database. On subsequent requests, `Language::loadLanguage()` constructs a file path using this value and executes it via `require`, achieving arbitrary PHP code execution as the web server user. Version 2.3.6 fixes the issue. |
CVE-2024-50420 | CRITICAL | 10.0 | 0.00515 | 40.18 | No | No | 2024-10-29 | 2026-05-11 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in aDirectory aDirectory adirectory allows Upload a Web Shell to a Web Server.…Unrestricted Upload of File with Dangerous Type vulnerability in aDirectory aDirectory adirectory allows Upload a Web Shell to a Web Server.This issue affects aDirectory: from n/a through <= 1.3. |
CVE-2024-50496 | CRITICAL | 10.0 | 0.00515 | 40.18 | No | No | 2024-10-28 | 2026-05-11 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to …Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through <= 6.6. |
CVE-2024-49291 | CRITICAL | 10.0 | 0.00511 | 40.18 | No | No | 2024-10-17 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Gora Tech LLC Cooked Pro.This issue affects Cooked Pro: from n/a before 1.8…Unrestricted Upload of File with Dangerous Type vulnerability in Gora Tech LLC Cooked Pro.This issue affects Cooked Pro: from n/a before 1.8.0. |
CVE-2023-35797 | CRITICAL | 9.8 | 0.02791 | 40.18 | No | No | 2023-07-03 | 2025-02-13 | euvd | Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider.
This issue affects Apache Airflow Apache…Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider.
This issue affects Apache Airflow Apache Hive Provider: before 6.1.1.
Before version 6.1.1 it was possible to bypass the security check to RCE via
principal parameter. For this to be exploited it requires access to modifying the connection details.
It is recommended updating provider version to 6.1.1 in order to avoid this vulnerability. |
CVE-2024-50525 | CRITICAL | 10.0 | 0.00515 | 40.18 | No | No | 2024-11-04 | 2026-05-11 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in helloprint Helloprint helloprint allows Upload a Web Shell to a Web Server.…Unrestricted Upload of File with Dangerous Type vulnerability in helloprint Helloprint helloprint allows Upload a Web Shell to a Web Server.This issue affects Helloprint: from n/a through <= 2.0.4. |
CVE-2022-45297 | CRITICAL | 9.8 | 0.02798 | 40.18 | No | No | 2023-01-31 | 2025-03-27 | euvd | EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter. |
CVE-2025-12275 | CRITICAL | 10.0 | 0.00508 | 40.18 | No | No | 2025-10-26 | 2025-10-28 | euvd | Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
CVE-2025-10363 | CRITICAL | 10.0 | 0.00519 | 40.18 | No | No | 2025-10-06 | 2025-10-06 | euvd | Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This i…Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This issue affects at least Topal Finanzbuchhaltung: 10.1.5.20 and is fixed in version 11.2.12.00 |
CVE-2023-34976 | CRITICAL | 10.0 | 0.00509 | 40.18 | No | No | 2023-10-13 | 2026-01-12 | euvd | A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to …A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We have already fixed the vulnerability in the following version:
Video Station 5.7.0 ( 2023/07/27 ) and later |
CVE-2020-10921 | CRITICAL | 9.8 | 0.02808 | 40.18 | No | No | 2020-07-23 | 2024-08-04 | euvd | This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen …This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the lack of authentication prior to allowing alterations to the system configuration. An attacker can leverage this vulnerability to issue commands to the physical equipment controlled by the device. Was ZDI-CAN-10482. |
CVE-2025-39401 | CRITICAL | 10.0 | 0.00502 | 40.18 | No | No | 2025-05-19 | 2026-05-12 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web Shell to a Web Serv…Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023). |
CVE-2024-50527 | CRITICAL | 10.0 | 0.00515 | 40.18 | No | No | 2024-11-04 | 2026-05-11 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a …Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell to a Web Server.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3. |
CVE-2024-49257 | CRITICAL | 10.0 | 0.00511 | 40.18 | No | No | 2024-10-16 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Upload a Web Shell to a …Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Upload a Web Shell to a Web Server.This issue affects Azz Anonim Posting: from n/a through <= 0.9. |
CVE-2024-49326 | CRITICAL | 10.0 | 0.00516 | 40.18 | No | No | 2024-10-20 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Vasileios Kerasiotis Affiliator affiliator-lite allows Upload a Web Shell t…Unrestricted Upload of File with Dangerous Type vulnerability in Vasileios Kerasiotis Affiliator affiliator-lite allows Upload a Web Shell to a Web Server.This issue affects Affiliator: from n/a through <= 2.1.3. |
CVE-2024-49610 | CRITICAL | 10.0 | 0.00516 | 40.18 | No | No | 2024-10-20 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in photokiteditor photokit photokit allows Upload a Web Shell to a Web Server.…Unrestricted Upload of File with Dangerous Type vulnerability in photokiteditor photokit photokit allows Upload a Web Shell to a Web Server.This issue affects photokit: from n/a through <= 1.0. |