Latest CVE Feed
-
9.8
CRITICALCVE-2025-22992
A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >= 11.6.9. The vulnerability is caused by improper handling of user-supplied input in the data query parameter, allowing attackers to execute arbitrary SQL comma... Read more
Affected Products : emoncms- Published: Feb. 06, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22882
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to leverage debugging logic to execute arbitrary code when parsing CBDGL file.... Read more
Affected Products : ispsoft- Published: Apr. 30, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22883
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.... Read more
Affected Products : ispsoft- Published: Apr. 30, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22946
Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead to remote arbitrary code execution.... Read more
- Published: Jan. 10, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22884
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an attacker to execute arbitrary code when parsing DVP file.... Read more
Affected Products : ispsoft- Published: Apr. 30, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22930
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.... Read more
Affected Products : opensis- Published: Apr. 03, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22916
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-22906
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.... Read more
- Published: Jan. 16, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22457
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.... Read more
- Actively Exploited
- Published: Apr. 03, 2025
- Modified: May. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-43269
pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.... Read more
Affected Products : pigcms- Published: Oct. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-22144
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved b... Read more
Affected Products : nameless- Published: Jan. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-21613
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary value... Read more
Affected Products : go-git- Published: Jan. 06, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-4402
The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No P... Read more
- Published: Oct. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-20682
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416937; ... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-20634
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User inter... Read more
- Published: Feb. 03, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-20260
A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arbitrary code on an affected device. This vulnerability... Read more
Affected Products : clamav- Published: Jun. 18, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1945
picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flipping specific bits in the ZIP file headers, an attacker can embed malicious pickle files that remain undetec... Read more
Affected Products : picklescan- Published: Mar. 10, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Supply Chain
-
9.8
CRITICALCVE-2025-1956
A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component Login. The manipulation of the argument password leads to sql injection. It is ... Read more
Affected Products : shopping_portal- Published: Mar. 04, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1942
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.... Read more
- Published: Mar. 04, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1901
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument username leads to sql injection. It i... Read more
Affected Products : restaurant_table_booking_system- Published: Mar. 04, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Injection