Latest CVE Feed
-
9.8
CRITICALCVE-2025-6840
A vulnerability, which was classified as critical, was found in code-projects Product Inventory System 1.0. This affects an unknown part of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. It is... Read more
Affected Products : product_inventory_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6844
A vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signin.php. The manipulation of the argument User leads to sql injection. The attack can... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6845
A vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /register1.php. The manipulation of the argument User leads to sql injection. The attack may be la... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6847
A vulnerability classified as critical was found in code-projects Simple Forum 1.0. This vulnerability affects unknown code of the file /forum_edit.php. The manipulation of the argument iii leads to sql injection. The attack can be initiated remotely. The... Read more
Affected Products : simple_forum- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6863
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument edi... Read more
Affected Products : local_services_search_engine_management_system- Published: Jun. 29, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9089
A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The ex... Read more
- Published: Aug. 17, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-8042
Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.... Read more
Affected Products : firefox- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-53299
Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer allows Object Injection. This issue affects ThemeMakers Visual Content Composer: from n/a through 1.5.8.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54713
Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce allows Authentication Abuse. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 1.3.0.... Read more
Affected Products : ecab_taxi_booking_manager- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-57155
Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-9298
A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The expl... Read more
- Published: Aug. 21, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-9299
A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseData of the file /goform/getMasterPassengerAnalyseData. The manipulation of the argument Time leads to stack-based buffer over... Read more
- Published: Aug. 21, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-9304
A weakness has been identified in SourceCodester Online Bank Management System 1.0. Impacted is an unknown function of the file /bank/show.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from a remote ... Read more
Affected Products : online_bank_management_system- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9311
A vulnerability was identified in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown functionality of the file /fair/addfair.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the atta... Read more
Affected Products : apartment_management_system- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-52352
Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-up option on the login page UI. However, the sign-up API endpoint remains publicly accessible and functio... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3128
A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete information in Mitsubishi Electric smartRTU, or cause a denial-of service condition on the product.... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-52786
An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL.... Read more
Affected Products :- Published: Aug. 22, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-29209
TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub_41105C function of cstecgi .cgi.... Read more
- Published: Apr. 18, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-28236
Nautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware update process. This vulnerability allows attackers to execute arbitrary code via supplying a crafted update package... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3799
A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousController.php. The manipulation of the argument email/username leads to sql injection. It is possible to launch ... Read more
Affected Products : wcms- Published: Apr. 19, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection