Latest CVE Feed
-
9.8
CRITICALCVE-2025-7169
A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknown function of the file /complainer_page.php. The manipulation of the argument location leads to sql injection. It is possible to launch... Read more
Affected Products : crime_reporting_system- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7170
A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attac... Read more
Affected Products : crime_reporting_system- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7171
A vulnerability, which was classified as critical, has been found in code-projects Crime Reporting System 1.0. Affected by this issue is some unknown functionality of the file /policelogin.php. The manipulation of the argument email leads to sql injection... Read more
Affected Products : crime_reporting_system- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7172
A vulnerability, which was classified as critical, was found in code-projects Crime Reporting System 1.0. This affects an unknown part of the file /headlogin.php. The manipulation of the argument email leads to sql injection. It is possible to initiate th... Read more
Affected Products : crime_reporting_system- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7173
A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-student.php. The manipulation of the argument Username leads to sql injection. The attack can be initia... Read more
Affected Products : library_system- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22777
Deserialization of Untrusted Data vulnerability in GiveWP GiveWP allows Object Injection.This issue affects GiveWP: from n/a through 3.19.3.... Read more
Affected Products : givewp- Published: Jan. 13, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-5743
An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve Play to execute arbitrary code. This issue affects Eve Play: through 1.1.42.... Read more
Affected Products :- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2018-3813
getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USER_ID and AVI_USER_PASSWORD fields via a direct request.... Read more
- EPSS Score: %0.42
- Published: Jan. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-23106
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HT... Read more
Affected Products : forticlientems- Published: Jan. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-47571
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.... Read more
Affected Products : fortimanager- Published: Jan. 14, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2023-5846
Franklin Fueling System TS-550 versions prior to 1.9.23.8960 are vulnerable to attackers decoding admin credentials, resulting in unauthenticated access to the device. ... Read more
- EPSS Score: %0.03
- Published: Nov. 02, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-13161
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.... Read more
Affected Products : endpoint_manager- Actively Exploited
- Published: Jan. 14, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-21307
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +10 more products- Published: Jan. 14, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2023-5865
Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.32
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-48856
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.... Read more
Affected Products : qnx_software_development_platform- Published: Jan. 14, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-57471
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute... Read more
- Published: Jan. 14, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-57479
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address update function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary com... Read more
- Published: Jan. 14, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-57482
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless network processing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute a... Read more
- Published: Jan. 14, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-57473
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address editing function. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary co... Read more
- Published: Jan. 14, 2025
- Modified: May. 27, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-9636
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible... Read more
Affected Products : comboblocks- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Authentication