Latest CVE Feed
-
9.8
CRITICALCVE-2024-13234
The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in all versions up to, and including, 2.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation... Read more
Affected Products : product_table- Published: Jan. 23, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-23006
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated a... Read more
Affected Products : sma1000_firmware sma8200v sma6200_firmware sma6200 sma6210_firmware sma6210 sma7200_firmware sma7200 sma7210_firmware sma7210 +6 more products- Actively Exploited
- Published: Jan. 23, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2023-46401
KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.... Read more
Affected Products : kwhotel- Published: Jan. 23, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2019-19791
In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.... Read more
Affected Products : lemonldap\- Published: May. 29, 2023
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2022-46599
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.... Read more
- Published: Dec. 30, 2022
- Modified: Apr. 11, 2025
-
9.8
CRITICALCVE-2025-26909
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through 5.4.01.... Read more
Affected Products : hide_my_wp_ghost- Published: Mar. 27, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-28138
The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.... Read more
- Published: Mar. 27, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-49002
DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohi... Read more
Affected Products : dataease- Published: Jun. 03, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-30365
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/socio/sistema/controller/query_geracao_auto.php, specifically in the query parameter. This vulnerabilit... Read more
Affected Products : wegia- Published: Mar. 27, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22398
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lead... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-28219
Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.... Read more
- Published: Mar. 28, 2025
- Modified: May. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-22526
Deserialization of Untrusted Data vulnerability in NotFound PHP/MySQL CPU performance statistics allows Object Injection. This issue affects PHP/MySQL CPU performance statistics: from n/a through 1.2.1.... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-38985
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via in... Read more
Affected Products : depath- Published: Mar. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-22953
A SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and 5.18.0.573/HCM2024. The injection is specifically in the filter parameter of the JsonFetcher.svc endpoint. An attacker can e... Read more
Affected Products : human_capital_management- Published: Mar. 28, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2927
A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been classified as critical. Affected is an unknown function of the file /parameter/getFileTypeList.jsp. The manipulation of the argument typename leads to sql injection. It is possible to la... Read more
Affected Products : cdg- Published: Mar. 28, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-28087
Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.... Read more
Affected Products : online_exam_system- Published: Mar. 28, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-2951
A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the file /api/data.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The ... Read more
Affected Products : micro_mall- Published: Mar. 30, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26689
Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a specially crafted HTTP request to the product, the product data may be obtained or deleted, and/or the product settings may be... Read more
Affected Products :- Published: Mar. 31, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-22938
Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.... Read more
- Published: Mar. 31, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-31116
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The mitigation for CVE-2024-29190 in valid_host() uses socket.gethostbyname(), which is vulnerable to... Read more
Affected Products : mobile_security_framework- Published: Mar. 31, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Server-Side Request Forgery