Latest CVE Feed
-
9.8
CRITICALCVE-2022-28497
TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted requ... Read more
- EPSS Score: %0.18
- Published: Mar. 23, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17713
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp paramete... Read more
Affected Products : trape- EPSS Score: %0.36
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17413
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUBackupTa... Read more
Affected Products : netvault_backup- EPSS Score: %20.96
- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2003-0174
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been provided by an LDAP server, which could allow attackers to log in without a password.... Read more
Affected Products : irix- EPSS Score: %0.36
- Published: May. 12, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2015-9335
The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.... Read more
Affected Products : limit_attempts- EPSS Score: %0.55
- Published: Aug. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10283
The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order to maintain backwards compatibility, GCS and autopilot negotiate the version via the AUTOPILOT_VERSION mes... Read more
Affected Products : micro_air_vehicle_link- EPSS Score: %0.42
- Published: Aug. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12498
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.... Read more
Affected Products : icms- EPSS Score: %0.26
- Published: Jun. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-7131
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_employee_attendance. The manipulation of the argument empl... Read more
Affected Products : payroll_management_system- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-27845
In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated ... Read more
Affected Products : weblogic_server- EPSS Score: %91.62
- Published: Jan. 27, 2017
- Modified: Aug. 13, 2025
-
9.8
CRITICALCVE-2025-40600
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.... Read more
Affected Products : sonicos nsa_2700 nsa_3700 nsa_4700 nsa_5700 nsa_6700 nssp_10700 nssp_11700 nssp_13700 tz270 +13 more products- Published: Jul. 29, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2024-2048
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certifica... Read more
Affected Products : vault- Published: Mar. 04, 2024
- Modified: Aug. 06, 2025
-
9.8
CRITICALCVE-2023-43091
A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.... Read more
Affected Products : gnome-maps- Published: Nov. 17, 2024
- Modified: Aug. 06, 2025
-
9.8
CRITICALCVE-2025-8443
A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack may be ... Read more
Affected Products : online_medicine_guide- Published: Aug. 01, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8466
A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /forgot_passfarmer.php. The manipulation of the argument email leads to sql injection. It is possible to lau... Read more
Affected Products : online_farm_system- Published: Aug. 02, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4447
In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.... Read more
Affected Products : openj9- Published: May. 09, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-8374
A vulnerability was found in code-projects Vehicle Management 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /addcompany.php. The manipulation of the argument company leads to sql injection. The attack can be in... Read more
- Published: Jul. 31, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7814
A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability affects unknown code of the file /pages/signup_function.php. The manipulation of the argument fname leads to sql injection. The attack ca... Read more
Affected Products : food_ordering_review_system- Published: Jul. 18, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7673
A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior to V5.50(ABOM.5)C0 could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and potentially execute arbitra... Read more
Affected Products : vmg8825-t50k_firmware- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-7461
A vulnerability was found in code-projects Modern Bag 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /action.php. The manipulation of the argument proId leads to sql injection. The attack may be launched r... Read more
Affected Products : modern_bag- Published: Jul. 12, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection