Latest CVE Feed
-
9.3
CRITICALCVE-2024-52474
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LLC «TriIncom» Express Payments Module allows Blind SQL Injection.This issue affects Express Payments Module: from n/a through 1.1.8.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
9.3
CRITICALCVE-2024-54215
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Roninwp Revy.This issue affects Revy: from n/a through 1.18.... Read more
Affected Products : revy- Published: Dec. 09, 2024
- Modified: Dec. 20, 2024
-
9.3
CRITICALCVE-2024-55547
SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.... Read more
Affected Products :- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
9.3
CRITICALCVE-2024-50339
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all the sessions IDs and use them to steal any valid session. Version 10.0.17 contains a patch for this i... Read more
Affected Products : glpi- Published: Dec. 12, 2024
- Modified: Jan. 10, 2025
-
9.3
CRITICALCVE-2024-54361
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in outstrip Instant Appointment allows SQL Injection.This issue affects Instant Appointment: from n/a through 1.2.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.3
CRITICALCVE-2024-55981
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nabajit Roy Nabz Image Gallery allows SQL Injection.This issue affects Nabz Image Gallery: from n/a through v1.00.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.3
CRITICALCVE-2024-55988
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through 1.0.9.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.3
CRITICALCVE-2024-56039
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes VibeBP allows SQL Injection.This issue affects VibeBP: from n/a before 1.9.9.7.7.... Read more
Affected Products :- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
9.3
CRITICALCVE-2024-56042
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS allows SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.5.3.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
9.3
CRITICALCVE-2024-56045
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
9.3
CRITICALCVE-2025-22275
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote log... Read more
Affected Products : iterm2- Published: Jan. 03, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Information Disclosure
-
9.3
CRITICALCVE-2024-43652
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701 Likelihood: Moderate – The <redacted... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2024-43654
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Command Injection as root This issue affects all Iocharger AC EV charger models on a firmware version before 2... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2024-49655
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound ARPrice allows SQL Injection. This issue affects ARPrice: from n/a through 4.0.3.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-23931
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WordPress Local SEO allows Blind SQL Injection. This issue affects WordPress Local SEO: from n/a through 2.3.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-24981
MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript code due to a bypass to the existing guards around the ... Read more
Affected Products :- Published: Feb. 06, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-24973
Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the logout process, authentication credentials remain in cookies even after a user has explicitl... Read more
Affected Products : nexkey- Published: Feb. 11, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2025-22290
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition allows SQL Injection. This issue affects LTL Freight Quotes – FreightQuote Edition: from n/a ... Read more
Affected Products :- Published: Feb. 16, 2025
- Modified: Feb. 16, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-25150
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.6.... Read more
Affected Products : ulisting- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-26535
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Bitcoin / AltCoin Payment Gateway for WooCommerce allows Blind SQL Injection. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommer... Read more
Affected Products : bitcoin_\/_altcoin_payment_gateway_for_woocommerce- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection