Latest CVE Feed
-
9.8
CRITICALCVE-2025-5356
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component BYE Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The e... Read more
- Published: May. 30, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5357
A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component PWD Command Handler. The manipulation leads to buffer overflow. The attack can be launched... Read more
- Published: May. 30, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5358
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /bwdates-reports-details.php. The manipulation of the argument fromdate/tod... Read more
Affected Products : cyber_cafe_management_system- Published: May. 30, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5359
A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /appointment-history.php. The manipulation of the argument ID leads to sql injection. It is possible to init... Read more
Affected Products : online_hospital_management_system- Published: May. 30, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5360
A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /book-appointment.php. The manipulation of the argument doctor leads to sql injection. The attack can ... Read more
Affected Products : online_hospital_management_system- Published: May. 30, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5364
A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /doctor/add-patient.php. The manipulation of the argument patname leads to sql inject... Read more
Affected Products : online_hospital_management_system- Published: May. 30, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5367
A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument Product leads to sql injection. The attack ca... Read more
- Published: May. 31, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4607
The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function. This is due to the use of a weak, low-entropy OTP mechanism in the forge... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4631
The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3. This makes it possible to trigger the save_object_as_user() function for objects wh... Read more
Affected Products :- Published: May. 31, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-5376
A vulnerability was found in SourceCodester Health Center Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /patient.php. The manipulation of the argument itr_no ... Read more
- Published: May. 31, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-20674
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Pat... Read more
Affected Products : openwrt mt7915_firmware mt7916_firmware mt7981_firmware mt7986_firmware mt6890 mt6990 mt7915 mt7916 mt7986 +8 more products- Published: Jun. 02, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1750
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on t... Read more
Affected Products : llamaindex- Published: Jun. 02, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5443
A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function wirelessAdvancedHidden of the file /goform/wireless... Read more
Affected Products : re6500_firmware re6300_firmware re6300 re6500 re9000_firmware re9000 re6250_firmware re6250 re6350_firmware re6350 +2 more products- Published: Jun. 02, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-37089
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-51064
Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.... Read more
Affected Products : teachers_record_management_system- Published: Oct. 31, 2024
- Modified: Mar. 31, 2025
-
9.8
CRITICALCVE-2025-37092
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-37096
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.... Read more
Affected Products : storeonce_system- Published: Jun. 02, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4797
The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0. This is due to the plugin not properly validating a user's identity prior to setting a... Read more
Affected Products : golo- Published: Jun. 03, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-5509
A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload. The manipulation of the argument file/source leads to path traversal. It is possible to initiate the att... Read more
Affected Products : shiyi-blog- Published: Jun. 03, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-32106
In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.... Read more
- Published: Jun. 03, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Authentication