Latest CVE Feed
-
9.8
CRITICALCVE-2019-1072
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.... Read more
- Published: Jul. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-6424
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.... Read more
- Published: Jun. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-49851
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an Improper Authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product.... Read more
Affected Products : control_id_idsecure- Published: Jun. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-6611
A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/createBrand.php. The manipulation of the argument brandStatus leads to sql inject... Read more
Affected Products : inventory_management_system- Published: Jun. 25, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6612
A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /php_action/removeCategories.php. The manipulation of the argument categoriesId leads to sql ... Read more
Affected Products : inventory_management_system- Published: Jun. 25, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-5282
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file seed_message_student.php. The manipulation of the argument teacher_id leads to sql injection. Th... Read more
Affected Products : engineers_online_portal- Published: Sep. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-6618
A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function SetWLanApcliSettings of the file wps.so. The manipulation of the argument PIN leads to os command injection. It is possible to launch th... Read more
- Published: Jun. 25, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6621
A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This affects the function QuickSetting of the file ap.so. The manipulation of the argument hour/minute leads to os command injection. It is possible to initiate the atta... Read more
- Published: Jun. 25, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-5277
A vulnerability, which was classified as critical, has been found in SourceCodester Engineers Online Portal 1.0. This issue affects some unknown processing of the file student_avatar.php. The manipulation of the argument change leads to unrestricted uploa... Read more
Affected Products : engineers_online_portal- Published: Sep. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-4334
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possibl... Read more
Affected Products : simple_user_registration- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-49003
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take advantage of a feature in Java in which the character "ı" becomes "I" when converted to uppercase, and the character "ſ" become... Read more
Affected Products : dataease- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-29331
An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates... Read more
Affected Products : 3x-ui- Published: Jun. 26, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2014-7210
pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.... Read more
- Published: Jun. 26, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-3699
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation G-50 Version 3.37 and prior, G-50-W Version 3.37 and prior, G-50A Version 3.37 and prior, GB-50 Version 3.37 and prior, GB-50A Version 3.37 and prior, GB-24A Ver... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-6688
The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying a user's identity prior to logging them in through the create_user() function. This makes it possib... Read more
Affected Products : simple_payment- Published: Jun. 27, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-32281
Missing Authorization vulnerability in FocuxTheme WPKit For Elementor allows Privilege Escalation. This issue affects WPKit For Elementor: from n/a through 1.1.0.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-52724
Deserialization of Untrusted Data vulnerability in BoldThemes Amwerk allows Object Injection. This issue affects Amwerk: from n/a through 1.2.0.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-52725
Deserialization of Untrusted Data vulnerability in pebas CouponXxL allows Object Injection. This issue affects CouponXxL: from n/a through 3.0.0.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-12364
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Software Guest Tracking Software allows SQL Injection.This issue affects . NOTE: The vendor did not inform about the completion of the fixing... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2023-6014
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.... Read more
Affected Products : mlflow- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024