Latest CVE Feed
-
9.8
CRITICALCVE-2025-43928
In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 ... Read more
- Published: Apr. 20, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-29660
A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially... Read more
- Published: Apr. 21, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-46247
Missing Authorization vulnerability in codepeople Appointment Booking Calendar allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Appointment Booking Calendar: from n/a through 1.3.92.... Read more
Affected Products : appointment_booking_calendar- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28024
TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-43946
TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).... Read more
Affected Products : ddi- Published: Apr. 22, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-37087
A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.... Read more
Affected Products :- Published: Apr. 22, 2025
- Modified: May. 01, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-45428
In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.... Read more
- Published: Apr. 23, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-32966
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.8.... Read more
Affected Products : dataease- Published: Apr. 23, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-32969
XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitrary SQ... Read more
Affected Products : xwiki- Published: Apr. 23, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45429
In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.... Read more
- Published: Apr. 23, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-3603
The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like passwor... Read more
Affected Products : flynax_bridge- Published: Apr. 24, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3604
The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. ... Read more
Affected Products : flynax_bridge- Published: Apr. 24, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-46273
UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.... Read more
Affected Products :- Published: Apr. 24, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-46274
UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.... Read more
Affected Products :- Published: Apr. 24, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2470
The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 5.1. This is due to a lack of restriction on user role in t... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-46433
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible... Read more
Affected Products : teamcity- Published: Apr. 25, 2025
- Modified: May. 16, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-3969
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument ca... Read more
Affected Products : news_publishing_site_dashboard- Published: Apr. 27, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3971
A vulnerability classified as critical was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-phlebotomist.php. The manipulation of the argument empid leads to sql injecti... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3972
A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /bwdates-report-result.php. The manipulation of the argument todate lea... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3976
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /new-user-testing.php. The manipulation of the argument mobilenumber leads to sql injection. It ... Read more
Affected Products : covid19_testing_management_system- Published: Apr. 27, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection