Latest CVE Feed
-
9.8
CRITICALCVE-2025-22978
eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.... Read more
Affected Products : eladmin- Published: Feb. 03, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1009
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1016
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these coul... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1020
Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox... Read more
- Published: Feb. 04, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-0665
libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.... Read more
Affected Products : curl h410c_firmware h300s_firmware h500s_firmware h700s_firmware h410s_firmware bootstrap_os hci_compute_node h300s h410s +3 more products- Published: Feb. 05, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-57520
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-51547
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.... Read more
- Published: Feb. 06, 2025
- Modified: May. 23, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-57430
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this flaw can lead to unauthorized information disclosure, privile... Read more
Affected Products : cinema_booking_system- Published: Feb. 06, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-36555
Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me 2 KW-60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b allows malicious users to change the device IMEI-... Read more
Affected Products :- Published: Feb. 06, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0674
Multiple Elber products are affected by an authentication bypass vulnerability which allows unauthorized access to the password management functionality. Attackers can exploit this issue by manipulating the endpoint to overwrite any user's password wit... Read more
Affected Products :- Published: Feb. 07, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1061
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.16. This is due to insufficient verification on the user being supplied during the Apple OAuth authenticate request through the ... Read more
Affected Products :- Published: Feb. 07, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1168
A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-contact.php. The manipulation of the argument contact leads to sql i... Read more
Affected Products : contact_manager_with_export_to_vcf- Published: Feb. 11, 2025
- Modified: Feb. 18, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1177
A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import_add of the file dayrui/Fcms/Control/Admin/Linkage.php. The manipulation leads to deserialization. It is possible to launch the attack ... Read more
Affected Products : xunruicms- Published: Feb. 11, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-0180
The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3. This is due to the plugin not properly restricting what user meta can be updated during profile registration. This makes it possible fo... Read more
Affected Products : foodbakery- Published: Feb. 11, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2023-5457
A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical informa... Read more
Affected Products : imx6- Published: Mar. 05, 2024
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2025-28872
Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Block Spam By Math Reloaded: from n/a through 2.2.4.... Read more
Affected Products : block_spam_by_math_reloaded- Published: Mar. 11, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-2216
A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. Affected by this issue is the function UploadCrash of the file /crash/log/SaveCrash.ashx. The manipulation of the argument file leads t... Read more
Affected Products : warehouse_refinement_management_system- Published: Mar. 12, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-25568
SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is not in the VPN software, but is instead in a separate tool that has no u... Read more
Affected Products : vpn- Published: Mar. 12, 2025
- Modified: Jul. 19, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-25292
ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vulnerability was found in ruby-saml prior to versions 1.12.4 and 1.18.0 due to a parser differential. ReXML and Nokogiri parse XML differ... Read more
- Published: Mar. 12, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2232
The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authentication bypass in all versions up to, and including, 1.2.8. This is due to insufficient role restrictions in the 'do_register_user' func... Read more
Affected Products : realteo- Published: Mar. 14, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Authentication