Latest CVE Feed
-
9.8
CRITICALCVE-2025-54952
An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially resulting in code execution or other undesirable effects. This issue affects ExecuTorch prior to commit 8f062... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-8356
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE), allowing the attacker to run arbitrary commands on the system.... Read more
Affected Products : freeflow_core- Published: Aug. 08, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-5095
Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing an attacker to take over the device. A password change request can be sent directly to the device's HTTP endpoint without providing ... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2019-19846
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.... Read more
Affected Products : joomla\!- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-8809
A vulnerability classified as critical has been found in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /addelidetails.php. The manipulation of the argument del leads to sql injection. It is possible to launch the att... Read more
Affected Products : online_medicine_guide- Published: Aug. 10, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8811
A vulnerability, which was classified as critical, has been found in code-projects Simple Art Gallery 1.0. Affected by this issue is some unknown functionality of the file /Admin/registration.php. The manipulation of the argument fname leads to sql inject... Read more
Affected Products : simple_art_gallery- Published: Aug. 10, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8853
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0527
A vulnerability classified as critical was found in code-projects Admission Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /signupconfirm.php. The manipulation of the argument in_eml leads to sql injection. T... Read more
- Published: Jan. 17, 2025
- Modified: Jan. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0532
A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /dashboard/admin/new_submit.php. The manipulation of the argument m_id leads to sql injection. It is possible ... Read more
- Published: Jan. 17, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-57031
WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0540
A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /expadd.php. The manipulation of the argument expcat leads to sql injection. The attack can be i... Read more
Affected Products : tailoring_management_system- Published: Jan. 17, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0541
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/edit_member.php. The manipulation of the argument name leads to sql injection. The attack m... Read more
- Published: Jan. 17, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-13375
The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.1.7. This is due to the plugin not properly validating a user's identity prior to updating their details like passwo... Read more
Affected Products :- Published: Jan. 18, 2025
- Modified: Jan. 18, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0563
A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been classified as critical. Affected is an unknown function of the file /dash/update.php. The manipulation of the argument uname leads to sql injection. It is possible to launch the a... Read more
Affected Products : fantasy-cricket- Published: Jan. 19, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0565
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The explo... Read more
Affected Products : zzcms- Published: Jan. 19, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0585
The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.... Read more
Affected Products :- Published: Jan. 20, 2025
- Modified: Jan. 20, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-45647
IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow could an unverified user to change the password of an expired user without prior knowledge of that password.... Read more
- Published: Jan. 20, 2025
- Modified: Jan. 29, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-49688
Deserialization of Untrusted Data vulnerability in NotFound ARPrice allows Object Injection. This issue affects ARPrice: from n/a through 4.0.3.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-42936
The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.... Read more
- Published: Jan. 21, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-21524
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with... Read more
Affected Products : jd_edwards_enterpriseone_tools- Published: Jan. 21, 2025
- Modified: Mar. 17, 2025
- Vuln Type: Authentication