Latest CVE Feed
- 
                                
                                
9.8
CRITICALCVE-2025-49201
A weak authentication in Fortinet FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to execute unauthorized code or commands via specially craf... Read more
- Published: Oct. 14, 2025
 - Modified: Oct. 15, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11420
A vulnerability was detected in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/edit_order_details.php. The manipulation of the argument order_id results in sql injection. The attack may be launched remotely. The e... Read more
- Published: Oct. 08, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-49901
Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1.... Read more
Affected Products : simple_link_directory- Published: Oct. 22, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11595
A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing manipulation of the argument mobilenumber results in sql injection. Remote exploitation of th... Read more
Affected Products : online_apartment_visitor_management_system- Published: Oct. 11, 2025
 - Modified: Oct. 20, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11347
A vulnerability was found in code-projects Student Crud Operation up to 3.3. This vulnerability affects the function move_uploaded_file of the file add.php of the component Add Student Page/Edit Student Page. Performing manipulation results in unrestricte... Read more
Affected Products : crud_operation_system- Published: Oct. 07, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
9.8
CRITICALCVE-2025-40765
A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password h... Read more
Affected Products : telecontrol_server_basic- Published: Oct. 14, 2025
 - Modified: Oct. 21, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
9.8
CRITICALCVE-2025-60772
Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to escalate privileges and lock out the legitimate administrator via crafted HTTP requests.... Read more
Affected Products :- Published: Oct. 21, 2025
 - Modified: Oct. 22, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11533
The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_register() function not restricting what user roles a user can register with. This makes it possible for unau... Read more
Affected Products :- Published: Oct. 11, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11601
A vulnerability was detected in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Performing manipulation of the argument Username results in sql injection. The attack can b... Read more
Affected Products : online_student_result_system- Published: Oct. 11, 2025
 - Modified: Oct. 20, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-12273
A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing manipulation of the argument page can lead to buffer overflow. The attack may be launched remotely.... Read more
- Published: Oct. 27, 2025
 - Modified: Oct. 28, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
9.8
CRITICALCVE-2025-35051
Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. According to the rec... Read more
- Published: Oct. 09, 2025
 - Modified: Oct. 14, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11584
A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown function of the file /searchjob.php. The manipulation of the argument txtspecialization leads to sql injection. Remote exploitation of the att... Read more
- Published: Oct. 10, 2025
 - Modified: Oct. 23, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11522
The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_u... Read more
Affected Products :- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.8
CRITICALCVE-2025-12257
A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some unknown processing of the file /view_result.php. The manipulation of the argument ID leads to sql injection. The attack is possible to b... Read more
Affected Products : online_student_result_system- Published: Oct. 27, 2025
 - Modified: Oct. 28, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-36386
IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application.... Read more
Affected Products : maximo_application_suite- Published: Oct. 28, 2025
 - Modified: Oct. 30, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11658
A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected is an unknown function of the file /assets/changeSllyabus.php. The manipulation of the argument File results in unrestric... Read more
Affected Products : school_management_system- Published: Oct. 13, 2025
 - Modified: Oct. 16, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
9.8
CRITICALCVE-2025-60307
code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.... Read more
Affected Products : computer_laboratory_system- Published: Oct. 10, 2025
 - Modified: Oct. 21, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11403
A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this issue is some unknown functionality of the file /del_booking.php. Performing manipulation of the argument ID results in sql injection. It is possible to in... Read more
Affected Products : hotel_and_lodge_management_system- Published: Oct. 07, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-57108
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been ... Read more
Affected Products :- Published: Oct. 31, 2025
 - Modified: Oct. 31, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11315
A vulnerability was found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this vulnerability is the function findUserPage of the file findUserPage.do. Performing manipulation of the argument sort results in sql injection.... Read more
Affected Products : data_leakage_prevention_system- Published: Oct. 06, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection