CVE-2023-5636 | CRITICAL | 9.8 | 0.01681 | 39.79 | No | No | 2023-12-01 | 2026-05-20 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection.
This issue affects E…Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection.
This issue affects Education Portal: before v1.1. |
CVE-2026-49975 | HIGH | 7.5 | 0.27984 | 39.79 | No | Yes | 2026-06-08 | 2026-08-05 | cnvd, euvd, nvd, packetstorm | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP req…Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. |
CVE-2023-39420 | CRITICAL | 9.9 | 0.00548 | 39.79 | No | No | 2023-09-07 | 2024-09-26 | euvd | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" ac…The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an attacker generate the daily password and connect to application customers. Given that this is an administrative account, anyone logging into a customer deployment has full, unrestricted access to the application. |
CVE-2024-23606 | CRITICAL | 9.8 | 0.01679 | 39.79 | No | No | 2024-02-20 | 2025-11-04 | euvd | An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (a…An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. |
CVE-2024-23305 | CRITICAL | 9.8 | 0.01684 | 39.79 | No | No | 2024-02-20 | 2025-11-04 | euvd | An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master …An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vmrk file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. |
CVE-2024-23809 | CRITICAL | 9.8 | 0.01679 | 39.79 | No | No | 2024-02-20 | 2025-11-04 | euvd | A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Br…A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. |
CVE-2024-3871 | CRITICAL | 9.8 | 0.01699 | 39.79 | No | No | 2024-04-16 | 2024-08-01 | euvd | The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that …The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities.
Successful exploitation of these flaws would allow remote unauthenticated attackers to gain remote code execution with elevated privileges on the affected devices.
This issue affects DVW-W02W2-E2 through version 2.5.2. |
CVE-2025-69691 | CRITICAL | 9.9 | 0.0053 | 39.79 | No | No | 2026-05-08 | 2026-05-08 | euvd | Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call…Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code. |
CVE-2020-22452 | CRITICAL | 9.8 | 0.01696 | 39.79 | No | No | 2023-01-26 | 2026-07-09 | euvd | SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engin…SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php. |
CVE-2024-56059 | CRITICAL | 9.8 | 0.01693 | 39.79 | No | No | 2024-12-18 | 2026-04-28 | euvd | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allo…Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0. |
CVE-2023-23857 | CRITICAL | 9.9 | 0.00544 | 39.79 | No | No | 2023-03-14 | 2025-02-27 | euvd | Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open inter…Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and services across systems. On a successful exploitation, the attacker can read and modify some sensitive information but can also be used to lock up any element or operation of the system making that it unresponsive or unavailable. |
CVE-2025-25632 | CRITICAL | 9.8 | 0.01678 | 39.79 | No | No | 2025-03-05 | 2025-03-06 | euvd | Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet. |
CVE-2024-56058 | CRITICAL | 9.8 | 0.01693 | 39.79 | No | No | 2024-12-18 | 2026-04-28 | euvd | Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.This issue affects VRP…Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.This issue affects VRPConnector: from n/a through <= 2.0.1. |
CVE-2024-57225 | CRITICAL | 9.8 | 0.01678 | 39.79 | No | No | 2025-01-10 | 2025-01-13 | euvd | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function. |
CVE-2023-3047 | CRITICAL | 9.8 | 0.01679 | 39.79 | No | No | 2023-06-13 | 2026-05-22 | euvd | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection.
Th…Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection.
This issue affects Lockcell: before 15. |
CVE-2024-57224 | CRITICAL | 9.8 | 0.01678 | 39.79 | No | No | 2025-01-10 | 2025-01-13 | euvd | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps fu…Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function. |
CVE-2024-37418 | CRITICAL | 9.9 | 0.00537 | 39.79 | No | No | 2024-07-09 | 2026-04-29 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from …Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.6. |
CVE-2026-26137 | CRITICAL | 9.9 | 0.00539 | 39.79 | No | No | 2026-03-19 | 2026-06-19 | euvd | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. |
CVE-2023-50643 | CRITICAL | 9.8 | 0.01695 | 39.79 | No | No | 2024-01-09 | 2026-07-09 | euvd | An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnsp…An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components. |
CVE-2024-45490 | CRITICAL | 9.8 | 0.01686 | 39.79 | No | No | 2024-08-30 | 2026-07-14 | euvd | An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. |
CVE-2024-22891 | CRITICAL | 9.8 | 0.01686 | 39.79 | No | No | 2024-03-01 | 2024-08-29 | euvd | Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link. |
CVE-2023-29402 | CRITICAL | 9.8 | 0.01694 | 39.79 | No | No | 2023-06-08 | 2025-02-13 | euvd | The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program w…The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command, i.e. via "go get", are not affected (modules retrieved using GOPATH-mode, i.e. GO111MODULE=off, may be affected). |
CVE-2024-42737 | CRITICAL | 9.8 | 0.01677 | 39.79 | No | No | 2024-08-13 | 2024-08-13 | euvd | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Au…In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands. |
CVE-2026-72902 | CRITICAL | 9.9 | 0.00539 | 39.79 | No | No | 2026-08-10 | 2026-08-12 | euvd, nvd | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary c…Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands on a local or SSH-connected target server because registry.testRegistry and registry.testRegistryById in apps/dokploy/server/api/routers/registry.ts interpolate the password field into an execAsyncRemote shell command instead of using safeDockerLoginCommand. This issue is fixed in version 0.29.13. |
CVE-2023-52026 | CRITICAL | 9.8 | 0.01643 | 39.78 | No | No | 2024-01-12 | 2025-06-11 | euvd | TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled par…TOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parameter of the setTelnetCfg interface |
CVE-2022-24766 | CRITICAL | 9.8 | 0.01646 | 39.78 | No | No | 2022-03-21 | 2025-04-23 | euvd | mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.4 and below, a malicious client or server is able to perfo…mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.4 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through mitmproxy as part of another request/response's HTTP message body. While mitmproxy would only see one request, the target server would see multiple requests. A smuggled request is still captured as part of another request's body, but it does not appear in the request list and does not go through the usual mitmproxy event hooks, where users may have implemented custom access control checks or input sanitization. Unless mitmproxy is used to protect an HTTP/1 service, no action is required. The vulnerability has been fixed in mitmproxy 8.0.0 and above. There are currently no known workarounds. |
CVE-2024-49652 | CRITICAL | 9.9 | 0.00522 | 39.78 | No | No | 2024-10-23 | 2026-05-12 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Uploa…Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Upload a Web Shell to a Web Server.This issue affects 3D Work In Progress: from n/a through <= 1.0.3. |
CVE-2021-36336 | CRITICAL | 9.8 | 0.01655 | 39.78 | No | No | 2021-12-21 | 2024-09-16 | euvd | Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execu…Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system. |
CVE-2026-46850 | CRITICAL | 9.9 | 0.00521 | 39.78 | No | No | 2026-06-16 | 2026-06-18 | euvd | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.…Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Shell. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). |
CVE-2020-10270 | CRITICAL | 9.8 | 0.01656 | 39.78 | No | No | 2020-06-24 | 2024-09-17 | euvd | Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Da…Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Credentials to such wireless interface default to well known and widely spread users (omitted) and passwords (omitted). This information is also available in past User Guides and manuals which the vendor distributed. This flaw allows cyber attackers to take control of the robot remotely and make use of the default user interfaces MiR has created, lowering the complexity of attacks and making them available to entry-level attackers. More elaborated attacks can also be established by clearing authentication and sending network requests directly. We have confirmed this flaw in MiR100 and MiR200 but according to the vendor, it might also apply to MiR250, MiR500 and MiR1000. |
CVE-2025-7328 | CRITICAL | 9.9 | 0.0052 | 39.78 | No | No | 2025-10-14 | 2025-10-14 | euvd | Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks o…Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would no longer be able to communicate through NATR as a result of denial-of-service or NAT rule modifications. NAT rule modification could also result in device communication to incorrect endpoints. Admin account takeover could allow modification of configuration and require physical access to restore. |
CVE-2026-72738 | CRITICAL | 9.9 | 0.00521 | 39.78 | No | No | 2026-08-10 | 2026-08-10 | euvd, nvd | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/se…Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/server/api/routers/backup.ts passes the search parameter through normalizeS3Path and interpolates it into an rclone lsjson command executed by child_process.exec(), allowing an authenticated user with backup:read permission to execute arbitrary commands on the Dokploy host. This issue is fixed in version 0.29.13. |
CVE-2023-22894 | CRITICAL | 9.8 | 0.01658 | 39.78 | No | No | 2023-04-19 | 2025-11-07 | euvd | Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. Th…Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sensitive information for all API users but not other admin accounts. |
CVE-2026-72740 | CRITICAL | 9.9 | 0.00521 | 39.78 | No | No | 2026-08-10 | 2026-08-10 | euvd, nvd | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-…Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-controlled customGitUrl with sanitizeRepoPathSSH and interpolates its domain into the ssh-keyscan command from addHostToKnownHostsCommand without shell quoting, allowing an authenticated member with service deployment permission and an attached SSH key to execute arbitrary commands on the Dokploy host during deployment. This issue is fixed in version 0.29.13. |
CVE-2024-25421 | CRITICAL | 9.8 | 0.0165 | 39.78 | No | No | 2024-03-26 | 2024-08-07 | euvd | An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component. |
CVE-2026-8500 | CRITICAL | 9.8 | 0.01653 | 39.78 | No | No | 2026-05-13 | 2026-05-14 | euvd | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.
Web::Passwd is a small CGI application for managing htpasswd files using t…Web::Passwd versions through 0.03 for Perl is vulnerable to RCE.
Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command.
The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection. |
CVE-2023-35088 | CRITICAL | 9.8 | 0.01643 | 39.78 | No | No | 2023-07-25 | 2025-02-13 | euvd | Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLo…Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.
In the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks.
Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/8198 |
CVE-2025-22782 | CRITICAL | 9.9 | 0.0051 | 39.78 | No | No | 2025-01-15 | 2026-04-28 | euvd | Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-price-list-for-wooco…Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-price-list-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects WR Price List Manager For Woocommerce: from n/a through <= 1.0.8. |
CVE-2024-8463 | CRITICAL | 9.9 | 0.00513 | 39.78 | No | No | 2024-09-05 | 2024-09-05 | cnvd, euvd | File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to ex…File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell. |
CVE-2024-57686 | CRITICAL | 9.8 | 0.01645 | 39.78 | No | No | 2025-01-10 | 2025-02-11 | cnvd, euvd | A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allo…A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the "pagetitle" parameter. |
CVE-2026-32621 | CRITICAL | 9.9 | 0.00512 | 39.78 | No | Yes | 2026-03-13 | 2026-03-16 | euvd, github, packetstorm | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13…Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute Object.prototype in gateway directly by crafting operations with field aliases and/or variable names that target prototype-inheritable properties. Alternatively, if a subgraph were to be compromised by a malicious actor, they may be able to pollute Object.prototype in gateway by crafting JSON response payloads that target prototype-inheritable properties. This vulnerability is fixed in 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2. |
CVE-2022-37915 | CRITICAL | 9.8 | 0.01645 | 39.78 | No | No | 2022-10-28 | 2025-05-07 | euvd | A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote att…A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to a complete system compromise of Aruba EdgeConnect Enterprise Orchestration with versions 9.1.x branch only, Any 9.1.x Orchestrator instantiated as a new machine with a release prior to 9.1.3.40197, Orchestrators upgraded to 9.1.x were not affected. |
CVE-2026-46670 | CRITICAL | 9.8 | 0.01652 | 39.78 | No | No | 2026-08-11 | 2026-08-13 | euvd, nvd | YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManag…YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue. |
CVE-2023-52027 | CRITICAL | 9.8 | 0.01668 | 39.78 | No | No | 2024-01-11 | 2025-06-17 | euvd | TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost func…TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function. |
CVE-2026-40411 | CRITICAL | 9.9 | 0.00525 | 39.78 | No | No | 2026-05-22 | 2026-08-10 | euvd, nvd | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. |
CVE-2025-55343 | CRITICAL | 9.9 | 0.0051 | 39.78 | No | No | 2025-11-05 | 2025-11-05 | euvd | Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/b…Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqueda/busqueda.php txt_usua_codi, anexos_lista.php radi_temp, Administracion/listas/formArea_ajax.php codDepe, Administracion/listas/formDepeHijo_ajax.php codDepe, Administracion/listas/formDepePadre_ajax.php codInst, asociar_documentos/asociar_borrar_referencia.php radi_nume, asociar_documentos/asociar_documento_buscar_query.php radi_nume, asociar_documentos/asociar_documento_grabar.php txt_radi_nume, asociar_documentos/asociar_documento radi_nume, radicacion/buscar_usuario.php buscar_tipo, radicacion/formArea_ajax.php codDepe, radicacion/formDepeHijo_ajax.php codDepe, radicacion/formDepePadre_ajax.php codInst, radicacion/ver_datos_usuario.php destinatorio, reportes/reporte_TraspasoDocFisico.php verrad, tx/datos_imprimir_sobre.php txt_usua_codi, tx/datos_imprimir_sobre.php nume_radi_temp, tx/revertir_firma_digital_grabar.php txt_radi_nume, tx/tx_borrar_opcion_imp.php codigo_opc, tx/tx_realizar_tx.php txt_radicados, tx/tx_seguridad_documentos.php txt_radicados, or uploadFiles/cargar_doc_digitalizado_paginador.php txt_depe_codi. |
CVE-2024-31473 | CRITICAL | 9.8 | 0.01651 | 39.78 | No | No | 2024-05-14 | 2025-06-24 | euvd | There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code executi…There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system. |
CVE-2024-3549 | CRITICAL | 9.9 | 0.00515 | 39.78 | No | No | 2024-06-11 | 2026-04-08 | euvd | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter …The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. |
CVE-2026-30312 | CRITICAL | 9.8 | 0.01659 | 39.78 | No | No | 2026-03-31 | 2026-04-01 | euvd, nvd | DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechani…DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on string-based parsing to validate commands; while it intercepts dangerous operators such as ;, &&, ||, |, and command substitution patterns, it fails to account for raw newline characters embedded within the input. An attacker can construct a payload by embedding a literal newline between a whitelisted command and malicious code (e.g., git log malicious_command), forcing DSAI-Cline to misidentify it as a safe operation and automatically approve it. The underlying PowerShell interpreter treats the newline as a command separator, executing both commands sequentially, resulting in Remote Code Execution without any user interaction. |
CVE-2020-25848 | CRITICAL | 9.8 | 0.01654 | 39.78 | No | No | 2020-12-31 | 2024-09-17 | euvd | HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism. |