Latest CVE Feed
-
9.8
CRITICALCVE-2025-0213
A vulnerability was found in Campcodes Project Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forms/update_forms.php?action=change_pic2&id=4. The manipulation of the argument file leads to unr... Read more
Affected Products : project_management_system- Published: Jan. 04, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-13136
A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the file src/main/java/com/mysiteforme/admin/config/ShiroConfig.java. The manipulation leads to deserialization.... Read more
Affected Products : mysiteforme- Published: Jan. 05, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-0230
A vulnerability, which was classified as critical, was found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file /admin/print.php. The manipulation of the argument pid leads to sql injection. It is possible to launch th... Read more
Affected Products : responsive_hotel_site- Published: Jan. 05, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0233
A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/forms/course.php. The manipulation of the argument course_name leads to sql injection. It is possible ... Read more
Affected Products : project_management_system- Published: Jan. 05, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-13145
A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/site/blog/my/core/controller/admin/uploadController. java. The manipulation of the argument fil... Read more
- Published: Jan. 06, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2019-1785
A vulnerability in the RAR file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due ... Read more
Affected Products : clamav- Published: Apr. 08, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-30985
Deserialization of Untrusted Data vulnerability in NotFound GNUCommerce allows Object Injection. This issue affects GNUCommerce: from n/a through 1.5.4.... Read more
Affected Products : gnucommerce- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-28137
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-22900
Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-2567
An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling of ATG monitoring. This would result in potential safety hazards in fuel storage and transportation.... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-30206
Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service contains a hardcoded JWT secret in its default configuration, allowing attackers to generate valid JWT tokens and compromise the host mac... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-3495
Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker could easily brute force a session ID and load and execute arbitrary code.... Read more
Affected Products : commgr- Published: Apr. 16, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-3679
A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component HOST Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exp... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3689
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-customer-detailed.php. The manipulation of the argument editid leads to sql injection.... Read more
Affected Products : men_salon_management_system- Published: Apr. 16, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-40072
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.... Read more
Affected Products : online_id_generator_system- Published: Apr. 16, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-27539
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'VerifyUser' method. This could allow an unauthenticated remote attacker to bypa... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3723
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. This issue affects some unknown processing of the component MDTM Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit ... Read more
- Published: Apr. 16, 2025
- Modified: May. 12, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29708
SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.... Read more
- Published: Apr. 16, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-29040
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c... Read more
- Published: Apr. 17, 2025
- Modified: May. 01, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29041
An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c... Read more
- Published: Apr. 17, 2025
- Modified: May. 01, 2025
- Vuln Type: Memory Corruption