Latest CVE Feed
-
9.9
CRITICALCVE-2025-54049
Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP allows Privilege Escalation. This issue affects Custom API for WP: from n/a through 4.2.2.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-46616
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-46673
NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).... Read more
Affected Products : cryptolib- Published: Apr. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Cryptography
-
9.9
CRITICALCVE-2025-46674
NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.... Read more
Affected Products : cryptolib- Published: Apr. 27, 2025
- Modified: May. 29, 2025
- Vuln Type: Cryptography
-
9.9
CRITICALCVE-2024-37361
The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrus... Read more
Affected Products : pentaho_business_analytics_server- Published: Feb. 20, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-1265
An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privileges and perform code execution on affected system.... Read more
Affected Products :- Published: Feb. 20, 2025
- Modified: Feb. 20, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-42957
SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability eff... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-24775
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms allows Upload a Web Shell to a Web Server. This issue affects Forms: from n/a through 2.9.0.... Read more
Affected Products : forms- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-49887
Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce allows Remote Code Inclusion. This issue affects Product XML Feed Manager for WooCommerce: from n/a through 2.9.3.... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2022-43404
A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scr... Read more
Affected Products : script_security- EPSS Score: %0.08
- Published: Oct. 19, 2022
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2025-44961
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.... Read more
Affected Products : ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_m510 ruckus_r320 ruckus_r510 ruckus_r560 ruckus_r610 +21 more products- Published: Aug. 04, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-21556
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-20156
A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enf... Read more
Affected Products : meeting_management- Published: Jan. 22, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-30911
Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RomethemeKit For Elementor allows Command Injection. This issue affects RomethemeKit For Elementor: from n/a through 1.5.4.... Read more
Affected Products : romethemekit_for_elementor- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-49746
Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_machine_learning- Published: Jul. 18, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-49747
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_machine_learning- Published: Jul. 18, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-53762
Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.... Read more
- Published: Jul. 18, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-31330
SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks.... Read more
Affected Products :- Published: Apr. 08, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-32461
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The fixed versions are 21.12, 24.8, 27.2, and 28.3.... Read more
- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-32140
Unrestricted Upload of File with Dangerous Type vulnerability in Nirmal Kumar Ram WP Remote Thumbnail allows Upload a Web Shell to a Web Server. This issue affects WP Remote Thumbnail: from n/a through 1.3.1.... Read more
Affected Products :- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Misconfiguration