Latest CVE Feed
-
9.8
CRITICALCVE-2025-48890
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in miniigd SOAP service. If a remote unauthenticated attacker sends a specially crafted request to the affected p... Read more
Affected Products :- Published: Jun. 24, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-48744
In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.... Read more
Affected Products : pmb- Published: May. 27, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-48877
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the `stable` branch, version 3.5.0.beta5 of the `beta` branch, and version 3.5.0.beta6-dev of the `tests-passed` branch, Codepen is present in the default `allowed_iframes` site se... Read more
Affected Products : discourse- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-48709
An issue was discovered in BMC Control-M 9.0.21.300. When Control-M Server has a database connection, it runs DBUStatus.exe frequently, which then calls dbu_connection_details.vbs with the username, password, database hostname, and port written in clearte... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-48133
Missing Authorization vulnerability in Uncanny Owl Uncanny Automator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Automator: from n/a through 6.4.0.2.... Read more
Affected Products : uncanny_automator- Published: Jun. 05, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-48129
Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows Privilege Escalation. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: fro... Read more
Affected Products :- Published: Jun. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authorization
-
9.8
CRITICAL- Published: May. 27, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-47981
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +8 more products- Published: Jul. 08, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-47966
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : power_automate_for_desktop- Published: Jun. 05, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-47815
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.... Read more
Affected Products : pspp- Published: May. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-47917
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is documented as an output argument. The do... Read more
- Published: Jul. 20, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-47868
Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS repository. This standalone program is optional and neither part of NuttX RT... Read more
Affected Products : nuttx- Published: Jun. 16, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-47646
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Registration allows Password Recovery Exploitation. This issue affects PSW Front-end Login & Registration: from n/a through 1.13.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-47635
Server-Side Request Forgery (SSRF) vulnerability in WPWebinarSystem WebinarPress allows Server Side Request Forgery. This issue affects WebinarPress: from n/a through 1.33.27.... Read more
Affected Products : webinarpress- Published: May. 07, 2025
- Modified: May. 12, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-47581
Deserialization of Untrusted Data vulnerability in Elbisnero WordPress Events Calendar Registration & Tickets allows Object Injection.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through 2.6.0.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-47732
Microsoft Dataverse Remote Code Execution Vulnerability... Read more
Affected Products : dataverse- Published: May. 08, 2025
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-47582
Deserialization of Untrusted Data vulnerability in QuantumCloud WPBot Pro Wordpress Chatbot allows Object Injection.This issue affects WPBot Pro Wordpress Chatbot: from n/a through 12.7.0.... Read more
Affected Products : wpot- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-47814
libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.... Read more
Affected Products : pspp- Published: May. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-47436
Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompression logic, where specially crafted malformed ORC files can cause the decompressor to allocate a 250-byte buffer but then attempts to ... Read more
Affected Products : orc- Published: May. 14, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-47277
vLLM, an inference and serving engine for large language models (LLMs), has an issue in versions 0.6.5 through 0.8.4 that ONLY impacts environments using the `PyNcclPipe` KV cache transfer integration with the V0 engine. No other configurations are affect... Read more
Affected Products : vllm- Published: May. 20, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Misconfiguration