Latest CVE Feed
-
9.8
CRITICALCVE-2025-5170
A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5. This vulnerability affects the function AdminShitiListRequestVo of the file com\llisoft\controller\admin\shiti\AdminShitiController.java. The manipulation of the ar... Read more
Affected Products : mta_maita_training_system- Published: May. 26, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5052
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component LS Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. T... Read more
- Published: May. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5109
A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of the component STATUS Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploi... Read more
- Published: May. 23, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5057
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/insert-product.php. The manipulation of the argument Category leads to sql injection.... Read more
Affected Products : online_shopping_portal- Published: May. 21, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5178
A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected is an unknown function of the file /adm/ajax.php of the component Image File Handler. The manipulation of the argument files[] leads to ... Read more
Affected Products : queue_ticket_kiosk- Published: May. 26, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2022-40189
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to ... Read more
- Published: Nov. 22, 2022
- Modified: Apr. 29, 2025
-
9.8
CRITICALCVE-2025-5004
A vulnerability was found in projectworlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add_course.php. The manipulation of the argument c/subname leads to sql injection. The att... Read more
- Published: May. 20, 2025
- Modified: Aug. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-55306
GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could ... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-55294
screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command withou... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-55161
Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/markdown/pdf endpoint to convert Markdown to PDF, the backend calls a third-party tool to process it and... Read more
Affected Products : stirling_pdf- Published: Aug. 11, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-55591
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-55346
User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the host, by sending a simple POST request.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-55613
Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.... Read more
- Published: Aug. 22, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-54857
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge BASIC MB-A130 Ver.1.5.8 and earlier. If exploited, a remote unauthenticated attacker may execute arbitrary OS commands with root privilege... Read more
Affected Products : skybridge_basic_mb-a130_firmware- Published: Sep. 01, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54948
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.... Read more
Affected Products : apex_one- Actively Exploited
- Published: Aug. 05, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-54950
An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially result in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit b6b7a16df5e7852d976d8c34c8a7e9a1b... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-54802
pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path traversal in pyLoad-ng CNL Blueprint via package parameter, allowing Arbitrary File Write which leads to Remo... Read more
Affected Products : pyload- Published: Aug. 05, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-54452
Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-54442
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54454
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.... Read more
Affected Products : magicinfo_9_server- Published: Jul. 23, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Authentication