Latest CVE Feed
-
10.0
CRITICALCVE-2025-46337
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using A... Read more
Affected Products : adodb- Published: May. 01, 2025
- Modified: May. 26, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-41240
Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A ... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Misconfiguration
-
10.0
CRITICALCVE-2025-41672
A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain full access to the tool and all connected devices.... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-3499
The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary commands that are executed with administrative per... Read more
Affected Products :- Published: Jul. 09, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-39380
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).... Read more
Affected Products : hospital_management_system- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Misconfiguration
-
10.0
CRITICALCVE-2025-36535
The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.... Read more
Affected Products :- Published: May. 21, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-34300
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-34073
An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary operating system commands via the username parameter in a POST request to the /login endpoint. This occurs d... Read more
Affected Products :- Published: Jul. 02, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-34028
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Exe... Read more
- Actively Exploited
- Published: Apr. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Path Traversal
-
10.0
CRITICALCVE-2025-34153
Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET Remoting TCP channel. The service registers a listener on port 6031 with the URI en... Read more
Affected Products :- Published: Aug. 13, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2025-34067
An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT dese... Read more
Affected Products :- Published: Jul. 02, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-34035
An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject a... Read more
Affected Products : esr300_firmware esr300 esr350_firmware esr350 esr600_firmware esr600 esr900_firmware esr900 esr1200_firmware esr1200 +4 more products- Published: Jun. 24, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-30580
Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound DigiWidgets Image Editor allows Remote Code Inclusion. This issue affects DigiWidgets Image Editor: from n/a through 1.10.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-30065
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.... Read more
- Published: Apr. 01, 2025
- Modified: Jul. 28, 2025
-
10.0
CRITICALCVE-2025-30012
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then decode this mal... Read more
Affected Products :- Published: May. 13, 2025
- Modified: Jul. 07, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2025-2620
A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the function mod_graph_auth_uri_handler of the file /storage of the component Authentication Handler. The manipulation leads to stack-based buffe... Read more
- Published: Mar. 22, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Authentication
-
10.0
HIGHCVE-2025-2619
A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dws_cookie of the file /storage of the component Cookie Handler. The manipulation leads to stack-based buffer overflow. It is possible to... Read more
- Published: Mar. 22, 2025
- Modified: Mar. 26, 2025
- Vuln Type: Memory Corruption
-
10.0
CRITICALCVE-2025-2071
A critical OS Command Injection vulnerability has been identified in the FAST LTA Silent Brick WebUI, allowing remote attackers to execute arbitrary operating system commands via specially crafted input. This vulnerability arises due to improper handling ... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-29009
Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce allows Upload a Web Shell to a Web Server. This issue affects Medical Prescription Attachment Plugin for WooCommerce: from n/a t... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Misconfiguration
-
10.0
CRITICALCVE-2025-27364
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server tha... Read more
Affected Products : caldera- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Authentication