Latest CVE Feed
-
9.9
CRITICALCVE-2025-24775
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms allows Upload a Web Shell to a Web Server. This issue affects Forms: from n/a through 2.9.0.... Read more
Affected Products : forms- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-24677
Improper Control of Generation of Code ('Code Injection') vulnerability in WPSpins Post/Page Copying Tool allows Remote Code Inclusion. This issue affects Post/Page Copying Tool: from n/a through 2.0.3.... Read more
Affected Products :- Published: Feb. 04, 2025
- Modified: Feb. 04, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-23121
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user... Read more
Affected Products : veeam_backup_\&_replication- Published: Jun. 19, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-22782
Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce allows Upload a Web Shell to a Web Server.This issue affects WR Price List Manager For Woocommerce: from n/a through 1.0.8.... Read more
Affected Products :- Published: Jan. 15, 2025
- Modified: Jan. 15, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-21556
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-20156
A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enf... Read more
Affected Products : meeting_management- Published: Jan. 22, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-1265
An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privileges and perform code execution on affected system.... Read more
Affected Products :- Published: Feb. 20, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-1041
An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.... Read more
Affected Products : call_management_system- Published: Jun. 10, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-0867
The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that the system can startup on its own, the credentials of the administrator were stored. Consequently, the EPC2 user can execute any comma... Read more
Affected Products :- Published: Feb. 14, 2025
- Modified: Feb. 14, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-0781
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.... Read more
- Published: Jan. 28, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Path Traversal
-
9.9
CRITICALCVE-2024-9014
pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.... Read more
Affected Products : pgadmin- Published: Sep. 23, 2024
- Modified: Sep. 26, 2024
-
9.9
CRITICALCVE-2024-8672
The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that extends several page builders. This is due... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
9.9
CRITICALCVE-2024-8614
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated ... Read more
Affected Products : jobsearch_wp_job_board- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
9.9
CRITICALCVE-2024-6386
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it p... Read more
Affected Products : wpml- Published: Aug. 21, 2024
- Modified: Sep. 27, 2024
-
9.9
CRITICALCVE-2024-6327
In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.... Read more
- Published: Jul. 24, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-5853
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible ... Read more
Affected Products : sirv- Published: Jun. 19, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-0022
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.32
- Published: Jan. 10, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-46641
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function.... Read more
- EPSS Score: %1.87
- Published: Dec. 23, 2022
- Modified: Apr. 15, 2025
-
9.9
CRITICALCVE-2018-3876
An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 64 bytes. An atta... Read more
- EPSS Score: %0.48
- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2022-44588
Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress. ... Read more
Affected Products : cryptocurrency_widgets_pack- EPSS Score: %0.14
- Published: Dec. 15, 2022
- Modified: Nov. 21, 2024