Latest CVE Feed
-
9.8
CRITICALCVE-2025-4900
A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/payment.php. The manipulation of the argument cid leads to sql injection. It is possible to launch the at... Read more
Affected Products : sales_and_inventory_system- Published: May. 18, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4849
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been rated as critical. Affected by this issue is the function CloudACMunualUpdateUserdata of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument url leads to command inj... Read more
- Published: May. 18, 2025
- Modified: May. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4905
A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the function load_qc_pickl of the file basestation3/QC.py. The manipulation of the argument qc_file leads to deserialization. An attack has ... Read more
Affected Products : basestation- Published: May. 19, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4844
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unknown functionality of the component CD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. T... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4847
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component MLS Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The explo... Read more
- Published: May. 18, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4707
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pages/transaction_add.php. The manipulation of the argument prod_name leads to sql injection. The... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4717
A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /visitors-form.php. The manipulation of the argument fullname leads to sql injection. It is possi... Read more
Affected Products : company_visitor_management_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4773
A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/level.php. The manipulation of the argument level leads to sql injection. The attack... Read more
Affected Products : online_course_registration- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4789
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component LCD Command Handler. The manipulation leads to buffer overflow. The attack may be launched... Read more
- Published: May. 16, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-4766
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/profile.php. The manipulation of the argument contactnumber leads to sql inj... Read more
Affected Products : zoo_management_system- Published: May. 16, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4660
A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-bas... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4915
A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/auto-taxi-entry-detail.php. The manipulation of the argument price leads to sql inj... Read more
Affected Products : auto\/taxi_stand_management_system- Published: May. 19, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4864
A vulnerability has been found in itsourcecode Restaurant Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/finished.php. The manipulation of the argument ID leads to sql injection. The attack can... Read more
Affected Products : restaurant_management_system- Published: May. 18, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4771
A vulnerability, which was classified as critical, was found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/course.php. The manipulation of the argument coursecode leads to sql injection. It is possible to... Read more
Affected Products : online_course_registration- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4716
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pages/credit_transaction_add.php. The manipulation of the argument prod_name leads to s... Read more
Affected Products : sales_and_inventory_system- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4689
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclusion which leads to Remote Code Execution in all versions up to, and including, 4.89. This is due to the presence of a SQL Injection vul... Read more
Affected Products : ads_pro- Published: Jul. 02, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-4813
A vulnerability, which was classified as critical, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unknown function of the file /edit-phlebotomist.php. The manipulation of the argument mobilenumber leads to sql ... Read more
- Published: May. 16, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4606
The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.4. This is due to the theme not properly validating a user's identity prior to updating thei... Read more
Affected Products :- Published: Jul. 09, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4564
The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation via the 'delpdf' action in all versions up to, and including, 3.18. This makes it possible for unauthenticated a... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-4550
A vulnerability, which was classified as critical, has been found in PHPGurukul Apartment Visitors Management System 1.0. This issue affects some unknown processing of the file /admin/pass-details.php. The manipulation of the argument pid leads to sql inj... Read more
Affected Products : apartment_visitors_management_system- Published: May. 11, 2025
- Modified: May. 16, 2025
- Vuln Type: Injection