Latest CVE Feed
- 
                                
                                9.8CRITICALCVE-2025-35051Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. According to the rec... Read more - Published: Oct. 09, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Information Disclosure
 
- 
                                
                                9.8CRITICALCVE-2025-7526The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and inc... Read more Affected Products : wp_travel_engine- Published: Oct. 09, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Path Traversal
 
- 
                                
                                9.8CRITICALCVE-2025-11405A vulnerability was identified in SourceCodester Hotel and Lodge Management System 1.0. This vulnerability affects unknown code of the file /del_tax.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The... Read more Affected Products : hotel_and_lodge_management_system- Published: Oct. 07, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-35050Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. The vulnerable endpoint is used by New... Read more - Published: Oct. 09, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                9.8CRITICALCVE-2025-11473A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function of the file /edit_curr.php. Such manipulation of the argument currsymbol leads to sql injection. It is possible to launch the attack re... Read more Affected Products : hotel_and_lodge_management_system- Published: Oct. 08, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11345A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24, 9.14... Read more Affected Products : ilias- Published: Oct. 06, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-10041The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in thesave_qr_code_to_db() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attacke... Read more Affected Products :- Published: Oct. 15, 2025
- Modified: Oct. 16, 2025
- Vuln Type: Misconfiguration
 
- 
                                
                                9.8CRITICALCVE-2025-57515A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to inject arbitrary SQL commands via vulnerable input fields, enabling the execution of time-delay functions to infer database responses.... Read more Affected Products :- Published: Oct. 06, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11549A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. ... Read more - Published: Oct. 09, 2025
- Modified: Oct. 18, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                9.8CRITICALCVE-2025-11346A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack remote... Read more Affected Products : ilias- Published: Oct. 06, 2025
- Modified: Oct. 14, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-10547An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption.... Read more Affected Products :- Published: Oct. 03, 2025
- Modified: Oct. 16, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                9.8CRITICALCVE-2025-11604A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown processing of the file /all-orders.php. This manipulation of the argument Status causes sql injection. Remote exploitation of the attack is po... Read more Affected Products : online_food_ordering_system- Published: Oct. 11, 2025
- Modified: Oct. 20, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-11397A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /login.php. Performing manipulation of the argument email results in sql injection. The attack may be init... Read more Affected Products : hotel_and_lodge_management_system- Published: Oct. 07, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-9286The Appy Pie Connect for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the reset_user_password() REST handler in all versions up to, and including, 1.1.2. This makes it possible for unauthentica... Read more Affected Products :- Published: Oct. 03, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Authorization
 
- 
                                
                                9.8CRITICALCVE-2025-10587The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exi... Read more Affected Products : community_events- Published: Oct. 08, 2025
- Modified: Oct. 08, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-6388The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.2.14. This is due to the custom_actions() function not properly validating a user's identity prior to authenticating them to the site.... Read more Affected Products :- Published: Oct. 03, 2025
- Modified: Oct. 06, 2025
- Vuln Type: Authentication
 
- 
                                
                                9.8CRITICALCVE-2025-12240A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to buffer overflow. It is possible to initiate the attack... Read more - Published: Oct. 27, 2025
- Modified: Oct. 27, 2025
- Vuln Type: Memory Corruption
 
- 
                                
                                9.8CRITICALCVE-2025-10586The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exis... Read more Affected Products : community_events- Published: Oct. 09, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
- 
                                
                                9.8CRITICALCVE-2025-59943phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is oft... Read more Affected Products : phpmyfaq- Published: Oct. 03, 2025
- Modified: Oct. 10, 2025
- Vuln Type: Authentication
 
- 
                                
                                9.8CRITICALCVE-2025-11475A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. Executing manipulation of the argument user_id can lead to sql injection. The attack... Read more Affected Products : advanced_library_management_system- Published: Oct. 08, 2025
- Modified: Oct. 09, 2025
- Vuln Type: Injection
 
 
                         
                         
                         
                                             
                                            