Latest CVE Feed
-
9.8
CRITICALCVE-2025-25734
Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.42, and v4.6.0.1211.28 was discovered to contain an unauthenticated EFI shell which allows attackers to execute arbitrary code or escalate privileges during the boot pr... Read more
Affected Products :- Published: Aug. 26, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-25775
Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.... Read more
Affected Products : bus_ticket_booking_system- Published: Apr. 25, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25668
Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25663
A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow.... Read more
- Published: Feb. 20, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25763
crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php... Read more
Affected Products : crmeb- Published: Mar. 06, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26163
CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.... Read more
Affected Products : auto_atendimento- Published: Mar. 14, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25744
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetDynamicDNSSettings module.... Read more
- Published: Feb. 12, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25565
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the Supplier disputes this because the behavior only allows a user to attack himself by typing a long string on a command... Read more
Affected Products : vpn- Published: Mar. 12, 2025
- Modified: Jul. 19, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25686
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.... Read more
Affected Products : semcms- Published: Mar. 27, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25521
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.... Read more
Affected Products : seacms- Published: Feb. 25, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25403
Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php.... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25790
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.... Read more
Affected Products : foxcms- Published: Feb. 26, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-25351
PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense parameter.... Read more
Affected Products : daily_expense_tracker_system- Published: Feb. 12, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25742
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPassword parameter in the SetSysEmailSettings module.... Read more
- Published: Feb. 12, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25362
A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.... Read more
Affected Products :- Published: Mar. 05, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25388
A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the editid GET request parameter.... Read more
Affected Products : land_record_system- Published: Feb. 13, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25167
Missing Authorization vulnerability in blackandwhitedigital BookPress – For Book Authors allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BookPress – For Book Authors: from n/a through 1.2.7.... Read more
- Published: Feb. 07, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-25530
Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which is related to saving parental control configuration information. Attackers who successfully exploit this vulnerability can cause the r... Read more
Affected Products :- Published: Feb. 11, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25211
Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-25163
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Zach Swetz Plugin A/B Image Optimizer allows Path Traversal. This issue affects Plugin A/B Image Optimizer: from n/a through 3.3.... Read more
Affected Products : plugin_a\/b_image_optimizer- Published: Feb. 07, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Path Traversal