Latest CVE Feed
-
9.8
CRITICALCVE-2025-22904
RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22941
A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root and execute arbitrary commands.... Read more
- Published: Mar. 31, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-43198
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/hi_block.asp function.... Read more
- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-22907
RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22992
A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL comma... Read more
Affected Products : emoncms- Published: Feb. 06, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22882
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.... Read more
Affected Products : ispsoft- Published: Apr. 30, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22883
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.... Read more
Affected Products : ispsoft- Published: Apr. 30, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22946
Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.... Read more
- Published: Jan. 10, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22884
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.... Read more
Affected Products : ispsoft- Published: Apr. 30, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22930
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.... Read more
Affected Products : opensis- Published: Apr. 03, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22916
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22906
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22457
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.... Read more
- Actively Exploited
- Published: Apr. 03, 2025
- Modified: May. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-43269
pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.... Read more
Affected Products : pigcms- Published: Oct. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-22144
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved b... Read more
Affected Products : nameless- Published: Jan. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-21613
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary value... Read more
Affected Products : go-git- Published: Jan. 06, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-4402
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No P... Read more
- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-21298
Windows OLE Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Jan. 14, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-21311
Windows NTLM V1 Elevation of Privilege Vulnerability... Read more
Affected Products : windows_server_2022_23h2 windows_server_23h2 windows_11_24h2 windows_server_2025- Published: Jan. 14, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-20682
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416937; ... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption