Latest CVE Feed
-
9.8
CRITICALCVE-2025-0299
A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_result.php. The manipulation of the argument s leads to sql injection. It is possible to launch the attack rem... Read more
- Published: Jan. 07, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0229
A vulnerability, which was classified as critical, has been found in code-projects Travel Management System 1.0. This issue affects some unknown processing of the file /enquiry.php. The manipulation of the argument pid/t1/t2/t3/t4/t5/t6/t7 leads to sql in... Read more
Affected Products : travel_management_system- Published: Jan. 05, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0349
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src/mac leads to stack-based buffer overflow. It is po... Read more
- Published: Jan. 09, 2025
- Modified: Mar. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-0181
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.7. This is due to the plugin not properly validating a user's identity prior to setting the current user and their au... Read more
Affected Products : foodbakery- Published: Feb. 11, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0247
Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox... Read more
- Published: Jan. 07, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-0147
Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation of privilege via network access.... Read more
Affected Products : meeting_software_development_kit video_software_development_kit workplace_desktop- Published: Jan. 30, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-0211
A vulnerability was found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument page leads to file inclusion. The a... Read more
Affected Products : school_faculty_scheduling_system- Published: Jan. 04, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-0456
The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all accounts and passwords.... Read more
Affected Products : airpass- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-9973
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=reports of the component Report Viewing Page. The manipulation of the argument date leads to ... Read more
Affected Products : online_eyewear_shop- Published: Oct. 15, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9924
The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthenticated remote attackers still can download arbitrary system files, which may be deleted subsequently .... Read more
Affected Products : oaklouds_portal- Published: Oct. 14, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9986
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file member_register.php. The manipulation of the argument fullname/username/password/email leads... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 21, 2024
-
9.8
CRITICALCVE-2024-9863
The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to re... Read more
Affected Products : otp_verification_with_firebase- Published: Oct. 17, 2024
- Modified: Oct. 18, 2024
-
9.8
CRITICALCVE-2024-9862
The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass author... Read more
Affected Products : otp_verification_with_firebase- Published: Oct. 17, 2024
- Modified: Jan. 28, 2025
-
9.8
CRITICALCVE-2024-9893
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 3.1.14. This is due to insufficient verification on the user being returned by the social login token. This makes it possible fo... Read more
Affected Products :- Published: Oct. 16, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-9794
A vulnerability, which was classified as critical, has been found in Codezips Online Shopping Portal 1.0. This issue affects some unknown processing of the file /update-image1.php. The manipulation of the argument productimage1 leads to unrestricted uploa... Read more
Affected Products : online_shopping_portal- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2023-41998
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.... Read more
Affected Products : udp- Published: Nov. 27, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-9822
The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to l... Read more
Affected Products : pedalo_connector- Published: Oct. 11, 2024
- Modified: Nov. 15, 2024
-
9.8
CRITICALCVE-2024-9812
A vulnerability classified as critical was found in code-projects Crud Operation System 1.0. This vulnerability affects unknown code of the file delete.php. The manipulation of the argument sid leads to sql injection. The attack can be initiated remotely.... Read more
Affected Products : crud_operation_system- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2024-9931
The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unau... Read more
Affected Products :- Published: Oct. 26, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2024-9707
The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it poss... Read more
Affected Products : hunk_companion- Published: Oct. 11, 2024
- Modified: Nov. 25, 2024