Latest CVE Feed
-
9.8
CRITICALCVE-2025-30472
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.... Read more
Affected Products : corosync- Published: Mar. 22, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-30406
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machin... Read more
Affected Products : centrestack- Actively Exploited
- Published: Apr. 03, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-30389
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_ai_bot_service- Published: Apr. 30, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-30457
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to create symlinks to protected regions of the disk.... Read more
Affected Products : macos- Published: Mar. 31, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-30433
This issue was addressed with improved access restrictions. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A shortcut may be able to access files that are normal... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-30461
An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.... Read more
Affected Products : macos- Published: Mar. 31, 2025
- Modified: Apr. 04, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-30424
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Deleting a conversation in Messages may expose user contact information in system logging.... Read more
Affected Products : macos- Published: Mar. 31, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-30361
WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to change a user's password without verifying the old password. This issue exists in the control.php endpoint and ... Read more
Affected Products : wegia- Published: Mar. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-30139
An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts a fixed SSID with default credentials that cannot be changed. This allows any nearby attacker to connect to the dashcam's network witho... Read more
- Published: Mar. 18, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-30016
SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Avai... Read more
Affected Products :- Published: Apr. 08, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2973
A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affects an unknown part of the file /Admin/student.php. The manipulation of the argument profile_image leads to unrestricted upload. It is po... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2941
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it possi... Read more
Affected Products : drag_and_drop_multiple_file_upload_for_woocommerce- Published: Apr. 05, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-2846
A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects the function registration of the file /oews/classes/Users.php?f=registration of the component Registration. The manipulation of the argu... Read more
Affected Products : online_eyewear_shop- Published: Mar. 27, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2798
The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to regis... Read more
Affected Products : woffice- Published: Apr. 04, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2831
A vulnerability has been found in mingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 up to d4836f6b49cd0ac79a4021b15ce99ff7229d4694 and classified as critical. This vulnerability affects the function getBookList of the file /admin/bookList?page=1&limit=10. The man... Read more
Affected Products : library_management_system- Published: Mar. 27, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2738
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/manage-scdetails.php. The manipulation of the argument namesc leads to sql injection. ... Read more
Affected Products : old_age_home_management_system- Published: Mar. 25, 2025
- Modified: May. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2684
A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. This issue affects some unknown processing of the file /search-report-details.php. The manipulation of the argument searchinput leads to sql... Read more
Affected Products : bank_locker_management_system- Published: Mar. 24, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2736
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/bwdates-report-details.php. The manipulation of the argument fromdate leads to s... Read more
Affected Products : old_age_home_management_system- Published: Mar. 25, 2025
- Modified: May. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2643
A vulnerability has been found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-art-type-detail.php?editid=1. The manipulation of the argument arttype leads to sql ... Read more
Affected Products : art_gallery_management_system- Published: Mar. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-30133
An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IROAD X View" app for authentication, but its HTTP server lacks this restriction. Once connected to the dashcam... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Authentication