Latest CVE Feed
-
9.3
CRITICALCVE-2024-55988
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amol Nirmala Waman Navayan CSV Export allows Blind SQL Injection.This issue affects Navayan CSV Export: from n/a through 1.0.9.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.3
CRITICALCVE-2024-56039
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes VibeBP allows SQL Injection.This issue affects VibeBP: from n/a before 1.9.9.7.7.... Read more
Affected Products :- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
9.3
CRITICALCVE-2024-56042
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS allows SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.5.3.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
9.3
CRITICALCVE-2024-56045
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.... Read more
Affected Products : wordpress_learning_management_system_- Published: Dec. 31, 2024
- Modified: Dec. 31, 2024
-
9.3
CRITICALCVE-2025-22275
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tmp/framer.txt file. This can occur for certain it2ssh and SSH Integration configurations, during remote log... Read more
Affected Products : iterm2- Published: Jan. 03, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Information Disclosure
-
9.3
CRITICALCVE-2024-43652
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Injection as root This issue affects Iocharger firmware for AC model chargers before version 24120701 Likelihood: Moderate – The <redacted... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2024-43654
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware for AC models allows OS Command Injection as root This issue affects all Iocharger AC EV charger models on a firmware version before 2... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2024-49655
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound ARPrice allows SQL Injection. This issue affects ARPrice: from n/a through 4.0.3.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-23931
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound WordPress Local SEO allows Blind SQL Injection. This issue affects WordPress Local SEO: from n/a through 2.3.... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-24981
MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript code due to a bypass to the existing guards around the ... Read more
Affected Products :- Published: Feb. 06, 2025
- Modified: Feb. 06, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2025-24973
Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the logout process, authentication credentials remain in cookies even after a user has explicitl... Read more
Affected Products : nexkey- Published: Feb. 11, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Authentication
-
9.3
CRITICALCVE-2025-22290
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition allows SQL Injection. This issue affects LTL Freight Quotes – FreightQuote Edition: from n/a ... Read more
Affected Products :- Published: Feb. 16, 2025
- Modified: Feb. 16, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-25150
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix uListing allows Blind SQL Injection. This issue affects uListing: from n/a through 2.1.6.... Read more
Affected Products : ulisting- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-26535
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Bitcoin / AltCoin Payment Gateway for WooCommerce allows Blind SQL Injection. This issue affects Bitcoin / AltCoin Payment Gateway for WooCommer... Read more
Affected Products : bitcoin_\/_altcoin_payment_gateway_for_woocommerce- Published: Mar. 03, 2025
- Modified: Mar. 03, 2025
- Vuln Type: Injection
-
9.3
HIGHCVE-2015-6617
Skia, as used in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 23648740.... Read more
Affected Products : android- Published: Dec. 08, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6619
The kernel in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, aka internal bug 23520714.... Read more
Affected Products : android- Published: Dec. 08, 2015
- Modified: Apr. 12, 2025
-
9.3
CRITICALCVE-2025-30876
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ads by WPQuads Ads by WPQuads allows SQL Injection. This issue affects Ads by WPQuads: from n/a through 2.0.87.1.... Read more
Affected Products : ads- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-31552
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker allows SQL Injection. This issue affects RSVPMarker : from n/a through 11.4.8.... Read more
Affected Products : rsvpmaker- Published: Apr. 01, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-31599
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N-Media Bulk Product Sync allows SQL Injection. This issue affects Bulk Product Sync: from n/a through 8.6.... Read more
Affected Products :- Published: Apr. 11, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-22371
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (SaaS Service) login page allows an unauthenticated remote attacker to Bypass Authentication and execute arbitrary SQL commands.This issu... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Injection