Latest CVE Feed
-
9.8
CRITICALCVE-2025-1104
A vulnerability has been found in D-Link DHP-W310AV 1.04 and classified as critical. This vulnerability affects unknown code. The manipulation leads to authentication bypass by spoofing. The attack can be initiated remotely. The exploit has been disclosed... Read more
- Published: Feb. 07, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1093
The AIHub theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the generate_image function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary ... Read more
Affected Products :- Published: Apr. 19, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1017
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary c... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1012
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Race Condition
-
9.8
CRITICALCVE-2025-0847
A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /index.php of the component Login. The manipulation of the argument email leads to sql in... Read more
Affected Products : employee_task_management_system- Published: Jan. 30, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0855
The PGS Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.8.0 via deserialization of untrusted input in the 'import_header' function. This makes it possible for unauthenticated attackers to inject a PH... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1100
A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to execute arbitrary code with root privileges via SSH.... Read more
Affected Products : maxtime- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0791
A vulnerability, which was classified as critical, has been found in ESAFENET CDG V5. This issue affects some unknown processing of the file /sdDoneDetail.jsp. The manipulation of the argument flowId leads to sql injection. The attack may be initiated rem... Read more
Affected Products : cdg- Published: Jan. 29, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0896
Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.... Read more
Affected Products : orthanc- Published: Feb. 13, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0634
Use After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.... Read more
Affected Products : rlottie- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-0564
A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /authenticate.php. The manipulation of the argument uname leads to sql injection. The ... Read more
Affected Products : fantasy-cricket- Published: Jan. 19, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0534
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Code/loginnew.php. The manipulation of the argument Username lea... Read more
Affected Products : campaign_management_system_platform_for_women- Published: Jan. 17, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0838
There exists a heap buffer overflow vulnerable in Abseil-cpp. The sized constructors, reserve(), and rehash() methods of absl::{flat,node}hash{set,map} did not impose an upper bound on their size argument. As a result, it was possible for a caller to pass... Read more
- Published: Feb. 21, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-0493
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthentic... Read more
Affected Products : multivendorx- Published: Jan. 31, 2025
- Modified: May. 23, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-0332
In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.... Read more
- Published: Feb. 12, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-0299
A vulnerability classified as critical has been found in code-projects Online Book Shop 1.0. Affected is an unknown function of the file /search_result.php. The manipulation of the argument s leads to sql injection. It is possible to launch the attack rem... Read more
- Published: Jan. 07, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0229
A vulnerability, which was classified as critical, has been found in code-projects Travel Management System 1.0. This issue affects some unknown processing of the file /enquiry.php. The manipulation of the argument pid/t1/t2/t3/t4/t5/t6/t7 leads to sql in... Read more
Affected Products : travel_management_system- Published: Jan. 05, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0349
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src/mac leads to stack-based buffer overflow. It is po... Read more
- Published: Jan. 09, 2025
- Modified: Mar. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-0181
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.7. This is due to the plugin not properly validating a user's identity prior to setting the current user and their au... Read more
Affected Products : foodbakery- Published: Feb. 11, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0247
Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox... Read more
- Published: Jan. 07, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Memory Corruption