Latest CVE Feed
-
9.9
CRITICALCVE-2025-30220
GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XM... Read more
- Published: Jun. 10, 2025
- Modified: Aug. 26, 2025
- Vuln Type: XML External Entity
-
9.9
CRITICALCVE-2025-21415
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_ai_face_service- Published: Jan. 29, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2024-12583
The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization... Read more
Affected Products :- Published: Jan. 04, 2025
- Modified: Jan. 04, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-31340
A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a m... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Path Traversal
-
9.9
CRITICALCVE-2025-27282
Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator allows Using Malicious Files. This issue affects Theme File Duplicator: from n/a through 1.3.... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-32583
Improper Control of Generation of Code ('Code Injection') vulnerability in termel PDF 2 Post allows Remote Code Inclusion. This issue affects PDF 2 Post: from n/a through 2.4.0.... Read more
Affected Products :- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
9.9
CRITICALCVE-2025-32682
Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG Lite allows Upload a Web Shell to a Web Server. This issue affects MapSVG Lite: from n/a through 8.5.34.... Read more
Affected Products : mapsvg_lite- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-47452
Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR allows Upload a Web Shell to a Web Server. This issue affects WP VR: from n/a through 8.5.26.... Read more
Affected Products : wp_vr- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
9.9
CRITICALCVE-2025-46157
An issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave request form... Read more
Affected Products : timetrax- Published: Jun. 18, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Authentication
-
9.9
CRITICALCVE-2025-4981
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via ... Read more
Affected Products : mattermost_server- Published: Jun. 20, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Path Traversal
-
9.9
CRITICALCVE-2025-54426
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and Curve25519ScalarMul precompiles incorrectly handle invalid Ristretto point representations. Instead of retu... Read more
Affected Products :- Published: Jul. 28, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cryptography
-
9.9
CRITICALCVE-2025-54381
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file upload processing system contains an SSRF vulnerability that allows unauthenticated remote attackers to for... Read more
Affected Products : bentoml- Published: Jul. 29, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Server-Side Request Forgery
-
9.9
CRITICALCVE-2018-18810
The Administrator Service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, and TIBCO Managed File Transfer Internet Server contains vulnerabilities where an authenticated user with specific privileges can gain access to crede... Read more
- Published: Dec. 11, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2019-17536
Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.... Read more
Affected Products : gila_cms- Published: Oct. 13, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2009-3616
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfe... Read more
- Published: Oct. 23, 2009
- Modified: Apr. 09, 2025
-
9.9
CRITICALCVE-2018-18556
A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execute the pppd binary with elevated (sudo) permissions. Certain input parameters are not properly validated. A malicious operator user can... Read more
Affected Products : vyos- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2019-1384
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security F... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows +1 more products- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2024-2044
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code ex... Read more
Affected Products : pgadmin- Published: Mar. 07, 2024
- Modified: Feb. 13, 2025
-
9.9
CRITICALCVE-2023-51422
Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webin... Read more
Affected Products : webinarignition- Published: Dec. 29, 2023
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2019-13343
Butor Portal before 1.0.27 is affected by a Path Traversal vulnerability leading to a pre-authentication arbitrary file download. Effectively, a remote anonymous user can download any file on servers running Butor Portal. WhiteLabelingServlet is responsib... Read more
Affected Products : portal- Published: Oct. 02, 2019
- Modified: Nov. 21, 2024