Latest CVE Feed
-
9.1
CRITICALCVE-2024-54285
Unrestricted Upload of File with Dangerous Type vulnerability in SeedProd LLC SeedProd Pro allows Upload a Web Shell to a Web Server.This issue affects SeedProd Pro: from n/a through 6.18.10.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024
-
9.1
CRITICALCVE-2024-55516
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issue is /upload_sysconfig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading... Read more
Affected Products : msg2300_firmware msg2300 msg2100e_firmware msg2100e msg2200_firmware msg2200 msg1200_firmware msg1200- Published: Dec. 17, 2024
- Modified: Apr. 28, 2025
-
9.1
CRITICALCVE-2024-56249
Unrestricted Upload of File with Dangerous Type vulnerability in Webdeclic WPMasterToolKit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through 1.13.1.... Read more
Affected Products :- Published: Jan. 02, 2025
- Modified: Jan. 02, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2024-13242
Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*.... Read more
Affected Products : swift_mailer- Published: Jan. 09, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2024-39795
Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request ... Read more
- Published: Jan. 14, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2024-53553
An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2022-43916
IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, and 12.7 Pods do not restrict network egress for Pods that are used for ... Read more
- Published: Jan. 30, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Misconfiguration
-
9.1
CRITICALCVE-2024-12267
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file deletion due to insufficient file path validation in the dnd_codedropz_upload_delete() function in all versions up to, and including, 1.3.... Read more
Affected Products : drag_and_drop_multiple_file_upload_-_contact_form_7- Published: Jan. 31, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2024-36556
Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R36CW_YDE_S4_A29_2_V1.0_2023.05.24_22.49.44_cob_b have a Hardcoded password vulnerability.... Read more
Affected Products :- Published: Feb. 06, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-24434
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security ... Read more
- Published: Feb. 11, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-1127
The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the filesystem.... Read more
Affected Products :- Published: Feb. 13, 2025
- Modified: Feb. 13, 2025
-
9.1
CRITICALCVE-2025-1599
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/app/profile_crud.php. The manipulation of the argument old_cat_img l... Read more
Affected Products : best_church_management_software- Published: Feb. 24, 2025
- Modified: Feb. 24, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2025-27673
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cookie Returned in Response Body OVE-20230524-0017.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2024-13904
The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' function. This makes it possible for unauthenticated attackers to make web requests to arbi... Read more
Affected Products : platform.ly_for_woocommerce- Published: Mar. 07, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Server-Side Request Forgery
-
9.1
CRITICALCVE-2024-11042
In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive ... Read more
Affected Products :- Published: Mar. 20, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2024-4990
In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration. This allows an attacker to instantiate arbitrary cl... Read more
Affected Products : yii- Published: Mar. 20, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2024-6829
A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitrary locations on the host server. The attacker can control `repo.path` and `... Read more
Affected Products : aim- Published: Mar. 20, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Path Traversal
-
9.1
CRITICALCVE-2025-24383
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to de... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.1
CRITICALCVE-2025-3202
A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/controller/system/SysNoticeController.java. The manipulation leads... Read more
Affected Products : ruoyi-ai- Published: Apr. 04, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-28233
Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract ses... Read more
Affected Products :- Published: Apr. 18, 2025
- Modified: Apr. 22, 2025