Latest CVE Feed
-
9.8
CRITICALCVE-2025-6441
The Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin for WordPress is vulnerable to unauthenticated login token generation due to a missing capability check on the `webinarignition_sign_in... Read more
Affected Products : webinarignition- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-4784
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This issue affects Tourtella: before 26.05.2025.... Read more
Affected Products : tourtella- Published: Jul. 24, 2025
- Modified: Jul. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-48732
An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can request a .phar file to trigger this vulnerability.... Read more
Affected Products : avideo- Published: Jul. 24, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-6260
The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the the... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-45777
An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request.... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8159
A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. This issue affects the function formLanguageChange of the file /goform/formLanguageChange of the component HTTP POST Request Handler. The manipulation of the argument curTime ... Read more
- Published: Jul. 25, 2025
- Modified: Sep. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2019-19249
Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.... Read more
Affected Products : querytree- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-29631
An issue in Gardyn 4 allows a remote attacker execute arbitrary code... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-46199
Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields... Read more
Affected Products : grav- Published: Jul. 25, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-8166
A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/index.php of the component HTTP POST Request Handler. The manipulation of the argument Username l... Read more
Affected Products : church_donation_system- Published: Jul. 25, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8168
A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function websAspInit of the file /goform/formSetWanPPPoE. The manipulation of the argument curTime leads to buffer overflow. The attack may be l... Read more
- Published: Jul. 25, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-8173
A vulnerability has been found in 1000 Projects ABC Courier Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /Add_reciver.php. The manipulation of the argument reciver_name leads to s... Read more
Affected Products : abc_courier_management_system- Published: Jul. 25, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6895
The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who ... Read more
Affected Products : melapress_login_security- Published: Jul. 26, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8179
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/changeimage.php. The manipulation of the argument editid leads... Read more
Affected Products : local_services_search_engine_management_system- Published: Jul. 26, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8184
A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formSetWanL2TPcallback of the file /goform/formSetWanL2TPtriggers of the component HTTP POST Request Handler. The manipulation leads to stac... Read more
- Published: Jul. 26, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-8232
A vulnerability, which was classified as critical, was found in code-projects Online Ordering System 1.0. Affected is an unknown function of the file /admin/delete_user.php. The manipulation of the argument ID leads to sql injection. It is possible to lau... Read more
- Published: Jul. 27, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8233
A vulnerability has been found in code-projects Online Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/user.php. The manipulation of the argument un leads to sql injection. The ... Read more
- Published: Jul. 27, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8234
A vulnerability was found in code-projects Online Ordering System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/delete_member.php. The manipulation of the argument ID leads to sql injection. The at... Read more
- Published: Jul. 27, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8235
A vulnerability was found in code-projects Online Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/product.php. The manipulation of the argument Name leads to sql injection. It is possible to initiat... Read more
- Published: Jul. 27, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8236
A vulnerability was found in code-projects Online Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit_product.php. The manipulation of the argument Name leads to sql injection. The attack ... Read more
- Published: Jul. 27, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection