CVE-2023-27992

The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2023-3316

A NULL pointer dereference in TIFFClose() is caused by a failure to open an output file (non-existent path or a path that requires permissions like /dev/null) while specifying zones.Read More ...

Continue Reading
CVE-2022-47586

Unauth. SQL Injection (SQLi) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin Read More ...

Continue Reading
CVE-2023-2907

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection.This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; AP ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - HIGH

CVE-2022-46850

Auth. (author+) Broken Access Control vulnerability leading to Arbitrary File Deletion in Nabil Lemsieh Easy Media Replace plugin Read More ...

Continue Reading
CVE-2023-3318

A vulnerability was found in SourceCodester Resort Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argum ...

Continue Reading
CVE-2023-33213

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Display Custom Fields – wpView plugin Read More ...

Continue Reading
CVE-2023-34373

Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Project Manager plugin Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: