Latest CVE Feed
-
9.8
CRITICALCVE-2025-2359
A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authoriza... Read more
- Published: Mar. 17, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-13789
The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via deserialization of untrusted input from the 'paramsv2' parameter. This makes it possible for unauthenticated attackers to inject a PHP Ob... Read more
- Published: Feb. 20, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2370
A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316. It has been declared as critical. Affected by this vulnerability is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliSsid... Read more
- Published: Mar. 17, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-2218
A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /api/system/other of the component Setting Handler. The manipulation leads to improper access controls. The... Read more
Affected Products : lovecards- Published: Mar. 12, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-2253
The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3. This is due to the plugin not properly validating a verification code value prior to updating their password through the imi... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2146
Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Sat... Read more
- Published: May. 26, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-2115
A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 3.1. Affected is the function ProcessRequest of the file /AcceptZip.ashx. The manipulation of the argument file leads to unrestricted upload. It ... Read more
Affected Products : warehouse_refinement_management_system- Published: Mar. 09, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-2219
A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /api/upload/image. The manipulation of the argument file leads to unrestricted upload. The attack may be init... Read more
Affected Products : lovecards- Published: Mar. 12, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-2113
A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Esqueceu a senha. The manipulation of the argument txtCPF leads to sql injection. Th... Read more
Affected Products : atsvd- Published: Mar. 09, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2094
A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliKey/key leads to os c... Read more
- Published: Mar. 07, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2059
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/booking-details.php. The manipulation of the argument ambulanceregnum leads t... Read more
Affected Products : emergency_ambulance_hiring_portal- Published: Mar. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2067
A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search.php. The manipulation of the argument key leads to sql injection. The attack may be ... Read more
Affected Products : life_insurance_management_system- Published: Mar. 07, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29953
Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deseriali... Read more
Affected Products : activemq_nms_openwire- Published: Apr. 18, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1593
A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to... Read more
Affected Products : best_employee_management_system- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-29709
SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio.... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-29647
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.... Read more
Affected Products : seacms- Published: Apr. 03, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29662
A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system code via remote network access.... Read more
Affected Products : landchat- Published: Apr. 17, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-29462
A buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile function calls the socketRead function to process HTTP request messages, resulting in the overwriting of a buffer on the ... Read more
- Published: Apr. 03, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29659
Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.... Read more
- Published: Apr. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29315
An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to execute privileged operations via a crafted request.... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization