Latest CVE Feed
-
9.8
CRITICALCVE-2025-7605
A vulnerability was found in code-projects AVL Rooms 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument first_name leads to sql injection. The attack may be l... Read more
Affected Products : avl_rooms- Published: Jul. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7606
A vulnerability classified as critical has been found in code-projects AVL Rooms 1.0. This affects an unknown part of the file /city.php. The manipulation of the argument city leads to sql injection. It is possible to initiate the attack remotely. The exp... Read more
Affected Products : avl_rooms- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7608
A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The manipulation of the argument user_email leads to sql injection. It is possible to launc... Read more
Affected Products : simple_shopping_cart- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-53101
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename temp... Read more
Affected Products : imagemagick- Published: Jul. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-27270
Missing Authorization vulnerability in NotFound Residential Address Detection allows Privilege Escalation. This issue affects Residential Address Detection: from n/a through 2.5.4.... Read more
Affected Products :- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-55532
Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue.... Read more
Affected Products : ranger- Published: Mar. 03, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1890
A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of the argument file leads... Read more
- Published: Mar. 04, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0912
The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.4 via deserialization of untrusted input from the Donation Form through the 'card_address' parameter. This makes it possible for una... Read more
Affected Products : givewp- Published: Mar. 04, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1903
A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file /cart_add.php. The manipulation of the argument id leads to sql injection. The attack may be initiated... Read more
Affected Products : online_shopping_website- Published: Mar. 04, 2025
- Modified: Mar. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1954
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument username lea... Read more
- Published: Mar. 04, 2025
- Modified: May. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26319
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.... Read more
Affected Products : flowise- Published: Mar. 04, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-1963
A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. The manipulation of the argument checkin leads to sql injection. The attack can be... Read more
Affected Products : online_hotel_booking- Published: Mar. 05, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-24924
Certain functionality within GMOD Apollo does not require authentication when passed with an administrative username... Read more
Affected Products :- Published: Mar. 05, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1964
A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been rated as critical. This issue affects some unknown processing of the file /booknow.php?roomname=Duplex. The manipulation of the argument checkin leads to sql injection. The a... Read more
Affected Products : online_hotel_booking- Published: Mar. 05, 2025
- Modified: May. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-1965
A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument emailusername leads to sql injection. It is possible to launch ... Read more
Affected Products : online_hotel_booking- Published: Mar. 05, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-27638
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0.2614 allows Hardcoded Password V-2024-013.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-27643
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.933 Application 20.0.2368 allows Hardcoded AWS API Key V-2024-006.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-27646
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Edit User Account Exposure V-2024-001.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2025-27647
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Addition of Partial Admin Users Without Authentication V-2024-002.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-27649
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.893 Application 20.0.2140 allows Incorrect Access Control: PHP V-2023-016.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authorization