Latest CVE Feed
-
9.9
CRITICALCVE-2024-0402
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a wo... Read more
Affected Products : gitlab- EPSS Score: %39.31
- Published: Jan. 26, 2024
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2023-6825
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback... Read more
- Published: Mar. 13, 2024
- Modified: Jan. 21, 2025
-
9.9
CRITICALCVE-2025-24290
Multiple Authenticated SQL Injection vulnerabilities found in UISP Application (Version 2.4.206 and earlier) could allow a malicious actor with low privileges to escalate privileges.... Read more
Affected Products :- Published: Jun. 29, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2024-46479
Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code execution.... Read more
Affected Products : supravizio_bpm- Published: Jan. 13, 2025
- Modified: Jan. 13, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-0070
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can ... Read more
Affected Products : netweaver_application_server_abap- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2024-57726
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.... Read more
Affected Products : simplehelp- Published: Jan. 15, 2025
- Modified: Jan. 31, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-0471
Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access to the machine, being able to access, modify and execute commands freely.... Read more
Affected Products : pmb- Published: Jan. 16, 2025
- Modified: May. 07, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2019-1365
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to ex... Read more
- EPSS Score: %1.50
- Published: Oct. 10, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-42001
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.... Read more
Affected Products : pingid_desktop- EPSS Score: %0.22
- Published: Apr. 30, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2025-20124
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the a... Read more
Affected Products : identity_services_engine- Published: Feb. 05, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-1107
Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a speci... Read more
Affected Products :- Published: Feb. 07, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-24016
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI p... Read more
Affected Products : wazuh- Actively Exploited
- Published: Feb. 10, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-29827
Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_automation- Published: May. 08, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-33025
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEDCOM ROX RX1400 (All versions < V2.16.5), RUGGEDCOM ROX RX1500 (All versions < V2.16.5), RUGGEDCOM ROX RX1501 (All ... Read more
Affected Products : ruggedcom_rox_mx5000_firmware ruggedcom_rox_rx1400_firmware ruggedcom_rox_rx1500_firmware ruggedcom_rox_rx1501_firmware ruggedcom_rox_rx1510_firmware ruggedcom_rox_rx1511_firmware ruggedcom_rox_rx1512_firmware ruggedcom_rox_rx1524_firmware ruggedcom_rox_rx1536_firmware ruggedcom_rox_rx5000_firmware +1 more products- Published: May. 13, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-25015
Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8... Read more
Affected Products : kibana- Published: Mar. 05, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-26872
Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Eximius allows Using Malicious Files.This issue affects Eximius: from n/a through 2.2.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-26892
Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.... Read more
Affected Products :- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-52207
PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-48169
Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine allows Remote Code Inclusion. This issue affects Code Engine: from n/a through 0.3.3.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-46616
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication