Latest CVE Feed
-
9.8
CRITICALCVE-2025-27135
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from the input and sends it directly to the database query. As of time of pub... Read more
Affected Products : ragflow- Published: Feb. 25, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25516
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.... Read more
Affected Products : seacms- Published: Feb. 25, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25517
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.... Read more
Affected Products : seacms- Published: Feb. 25, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25519
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.... Read more
Affected Products : seacms- Published: Feb. 25, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25520
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.... Read more
Affected Products : seacms- Published: Feb. 25, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2019-19950
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.... Read more
- Published: Dec. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19951
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.... Read more
- Published: Dec. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-5174
If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-st... Read more
- Published: Sep. 27, 2023
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2024-0489
A vulnerability was found in code-projects Fighting Cock Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/action/edit_chicken.php. The manipulation of the argument ref leads to sql inject... Read more
Affected Products : fighting_cock_information_system- Published: Jan. 13, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-51451
In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.... Read more
- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8924
A vulnerability was identified in Campcodes Online Water Billing System 1.0. This issue affects some unknown processing of the file /viewbill.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploi... Read more
Affected Products : online_water_billing_system- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8925
A vulnerability has been found in itsourcecode Sports Management System 1.0. Affected is an unknown function of the file /Admin/match.php. The manipulation of the argument code leads to sql injection. It is possible to launch the attack remotely. The expl... Read more
Affected Products : sports_management_system- Published: Aug. 13, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2019-19948
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.... Read more
- Published: Dec. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-8935
A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipulation of the argument Username leads to sql injection. The attack can be lau... Read more
Affected Products : sales_management_system- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8936
A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown functionality of the file /superstore/dist/dordupdate.php. The manipulation of the argument select2 leads to sql injection. The attack may ... Read more
Affected Products : sales_management_system- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8946
A vulnerability has been found in projectworlds Online Notes Sharing Platform 1.0. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument User leads to sql injection. The attack can be initiated remotely. The expl... Read more
Affected Products : online_notes_sharing_platform- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8947
A vulnerability was found in projectworlds Visitor Management System 1.0. This issue affects some unknown processing of the file /query_data.php. The manipulation of the argument dateF/dateP leads to sql injection. The attack may be initiated remotely. Th... Read more
Affected Products : visitor_management_system- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8954
A vulnerability was identified in PHPGurukul Hospital Management System 4.0. This affects an unknown part of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspecilization leads to sql injection. It is possible to initiate ... Read more
Affected Products : hospital_management_system- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-48293
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dylan Kuhn Geo Mashup allows PHP Local File Inclusion. This issue affects Geo Mashup: from n/a through 1.13.16.... Read more
Affected Products : geo_mashup- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-54686
Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio allows Object Injection. This issue affects Exertio: from n/a through 1.3.2.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection