Latest CVE Feed
- 
                                
                                
9.9
CRITICALCVE-2025-34267
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm e... Read more
Affected Products : flowise- Published: Oct. 14, 2025
 - Modified: Oct. 27, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.9
CRITICALCVE-2025-60306
code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.... Read more
Affected Products : simple_car_rental_system- Published: Oct. 10, 2025
 - Modified: Oct. 16, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.9
CRITICALCVE-2025-11539
Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object ... Read more
Affected Products : grafana-image-renderer- Published: Oct. 09, 2025
 - Modified: Oct. 09, 2025
 - Vuln Type: Path Traversal
 
 - 
                                
                                
9.9
CRITICALCVE-2025-44823
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.... Read more
Affected Products : log_server- Published: Oct. 07, 2025
 - Modified: Oct. 08, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
9.9
CRITICALCVE-2025-0987
Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection.This issue affects CVLand: from 2.1.0 through 20251103.... Read more
Affected Products : cvland- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
9.9
CRITICALCVE-2025-60957
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.... Read more
- Published: Oct. 06, 2025
 - Modified: Oct. 10, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-12463
An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19.... Read more
Affected Products :- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11953
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a PO... Read more
Affected Products :- Published: Nov. 03, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-63622
A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/admin/subcategory.php. This manipulation of the argument category causes SQL injection.... Read more
Affected Products : online_complaint_site- Published: Oct. 29, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-34516
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an unauthenticated attacker to obtain remote access. Ilevia has declined to service this vulnerability, and recommends that customers not... Read more
- Published: Oct. 16, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Authentication
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11710
A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunder... Read more
- Published: Oct. 14, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11708
Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.... Read more
- Published: Oct. 14, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Memory Corruption
 
 - 
                                
                                
9.8
CRITICALCVE-2025-12294
A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /delete_category.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The expl... Read more
Affected Products : point_of_sales- Published: Oct. 27, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-12293
A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the file /category.php. Such manipulation of the argument Category leads to sql injection. It is possible to launch the attack remotely. The... Read more
Affected Products : point_of_sales- Published: Oct. 27, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-12339
A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The manipulation of the argument pid leads to sql injection. Remote exploita... Read more
- Published: Oct. 28, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-12308
A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unknown functionality of the file /deletemessage.php. Performing manipulation of the argument message_id results in sql injection. It is p... Read more
Affected Products : nero_social_networking_site- Published: Oct. 27, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11665
A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulation results in os command injection. The attack may be initiated remotely. ... Read more
- Published: Oct. 13, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11318
A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This vulnerability affects unknown code of the file uploadWxFile.do. The manipulation of the argument File results in unrestricted upload. The attack... Read more
Affected Products : data_leakage_prevention_system- Published: Oct. 06, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11317
A vulnerability was identified in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. This affects the function findRolePage of the file findSingConfigPage.do. The manipulation of the argument sort leads to sql injection. The attack is poss... Read more
Affected Products : data_leakage_prevention_system- Published: Oct. 06, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
9.8
CRITICALCVE-2025-11316
A vulnerability was determined in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1.0. Affected by this issue is the function findCategoryPage of the file findCategoryPage.do. Executing manipulation of the argument tenantId can lead to sql i... Read more
Affected Products : data_leakage_prevention_system- Published: Oct. 06, 2025
 - Modified: Nov. 03, 2025
 - Vuln Type: Injection