Latest CVE Feed
-
9.8
CRITICALCVE-2025-7832
A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/offering.php. The manipulation of the argument trcode leads to sql injection. The attack can be init... Read more
Affected Products : church_donation_system- Published: Jul. 19, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7833
A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/giving.php. The manipulation of the argument Amount leads to sql injection. The ... Read more
Affected Products : church_donation_system- Published: Jul. 19, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7838
A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage_seat.php. The manipulation of the argument ID leads to sql injection... Read more
Affected Products : online_movie_theater_seat_reservation_system- Published: Jul. 19, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7859
A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects unknown code of the file /members/update_password_admin.php. The manipulation of the argument new_password leads to sql injection. The... Read more
Affected Products : church_donation_system- Published: Jul. 20, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7860
A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issue affects some unknown processing of the file /members/login_admin.php. The manipulation of the argument Username leads to sql injectio... Read more
Affected Products : church_donation_system- Published: Jul. 20, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7911
A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf of the file /upnp_ctrl.asp of the component jhttpd. The manipulation of the argument remove_ext_proto/remove_ext_port leads to stack-ba... Read more
- Published: Jul. 20, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-7343
The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6704
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the fir... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-7624
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active for Email and SFOS was upgraded from a version older than ... Read more
- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-46120
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates o... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-46121
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A re... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-7933
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/settings_update.php of the component Setting Handler. The manipulation of the argument ID leads to sql... Read more
Affected Products : sales_and_inventory_system- Published: Jul. 21, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2019-19750
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.... Read more
Affected Products : msos- Published: Dec. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-3349
A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SYST Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely.... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3351
A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation of the argument Username leads to sql inj... Read more
Affected Products : old_age_home_management_system- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3248
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.... Read more
Affected Products : langflow- Actively Exploited
- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3372
A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The ex... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-28408
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28410
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28412
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization