Latest CVE Feed
-
9.8
CRITICALCVE-2025-23318
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, data tam... Read more
- Published: Aug. 06, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22957
A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without any authentication. This vulnerability could potentially allow attackers to gain unauthorized access to the database and extract sensitiv... Read more
Affected Products : zzcms- Published: Jan. 31, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22926
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.... Read more
Affected Products : opensis- Published: Apr. 03, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-22904
RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22941
A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.... Read more
- Published: Mar. 31, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-43198
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/hi_block.asp function.... Read more
- EPSS Score: %0.70
- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-22907
RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22992
A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL comma... Read more
Affected Products : emoncms- Published: Feb. 06, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22882
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.... Read more
Affected Products : ispsoft- Published: Apr. 30, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22883
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.... Read more
Affected Products : ispsoft- Published: Apr. 30, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22946
Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.... Read more
- Published: Jan. 10, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22884
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.... Read more
Affected Products : ispsoft- Published: Apr. 30, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22930
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.... Read more
Affected Products : opensis- Published: Apr. 03, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22916
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22906
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22457
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.... Read more
- Actively Exploited
- Published: Apr. 03, 2025
- Modified: May. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-43269
pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.... Read more
Affected Products : pigcms- EPSS Score: %0.10
- Published: Oct. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-22144
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved b... Read more
Affected Products : nameless- Published: Jan. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-21624
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding the uploading of playlist cover images. Without proper ch... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-21613
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary value... Read more
Affected Products : go-git- Published: Jan. 06, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection