Latest CVE Feed
-
9.8
CRITICALCVE-2025-41032
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BAdmin%5D%5Busername%5D' parameter in /apprain/admin/manage/add/.... Read more
Affected Products : apprain- Published: Sep. 04, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9752
A security vulnerability has been detected in D-Link DIR-852 1.00CN B09. Impacted is the function soapcgi_main of the file soap.cgi of the component SOAP Service. Such manipulation of the argument service leads to os command injection. The attack can be l... Read more
- Published: Sep. 01, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-41433
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that the actual reprodu... Read more
Affected Products : tidb- Published: Sep. 03, 2024
- Modified: Sep. 04, 2025
-
9.8
CRITICALCVE-2025-41034
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-static-pages/create/.... Read more
Affected Products : apprain- Published: Sep. 04, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-32937
An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequen... Read more
- Published: Jul. 03, 2024
- Modified: Sep. 04, 2025
-
9.8
CRITICALCVE-2025-9749
A vulnerability was identified in HKritesh009 Grocery List Management Web App up to f491b681eb70d465f445c9a721415c965190f83b. This affects an unknown part of the file /src/update.php. The manipulation of the argument ID leads to sql injection. It is possi... Read more
Affected Products : grocery_list_management_web- Published: Aug. 31, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9678
A weakness has been identified in Campcodes Online Loan Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_borrower. This manipulation of the argument ID causes sql injection. It is possible to initiate ... Read more
Affected Products : online_loan_management_system- Published: Aug. 29, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-26026
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated ... Read more
Affected Products : big-ip_next_central_manager- Published: May. 08, 2024
- Modified: Sep. 04, 2025
-
9.8
CRITICALCVE-2025-48581
In VerifyNoOverlapInSessions of apexd.cpp, there is a possible way to block security updates through mainline installations due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. ... Read more
Affected Products : android- Published: Sep. 04, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-10914
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulat... Read more
Affected Products : dns-320_firmware dns-320 dns-320lw_firmware dns-320lw dns-325_firmware dns-325 dns-340l_firmware dns-340l- Published: Nov. 06, 2024
- Modified: Nov. 24, 2024
-
9.8
CRITICALCVE-2025-26416
In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex... Read more
Affected Products : android- Published: Sep. 02, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-57140
rsbi-pom 4.7 is vulnerable to SQL Injection in the /bi/service/model/DatasetService path.... Read more
Affected Products : ruisibi- Published: Sep. 02, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9679
A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack rem... Read more
Affected Products : student_information_system- Published: Aug. 30, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-10996
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/process_category_edit.php. The manipulation of the argument cat leads to sql injection. It is p... Read more
- Published: Nov. 08, 2024
- Modified: Nov. 13, 2024
-
9.8
CRITICALCVE-2024-48050
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.... Read more
Affected Products : agentscope- Published: Nov. 04, 2024
- Modified: Sep. 04, 2025
-
9.8
CRITICALCVE-2024-10547
The WP Membership plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the user_profile_image_upload() function in all versions up to, and including, 1.6.2. This makes it possible for unauthenticated attacker... Read more
Affected Products :- Published: Nov. 09, 2024
- Modified: Nov. 12, 2024
-
9.8
CRITICALCVE-2025-9744
A weakness has been identified in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulation of the argument Username can lead to sql injection. The attack can be lau... Read more
Affected Products : online_loan_management_system- Published: Aug. 31, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9692
A vulnerability was found in Campcodes Online Shopping System 1.0. Affected is an unknown function of the file /product.php. Performing manipulation of the argument p results in sql injection. The attack may be initiated remotely. The exploit has been mad... Read more
Affected Products : online_shopping_system- Published: Aug. 30, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-32444
Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes allows Privilege Escalation.This issue affects RealHomes: from n/a through 4.3.6.... Read more
Affected Products :- Published: Sep. 03, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2022-27862
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.... Read more
Affected Products : vikbooking_hotel_booking_engine_\&_property_management_system_plugin- Published: Apr. 19, 2022
- Modified: Nov. 21, 2024