Latest CVE Feed
-
9.8
CRITICALCVE-2025-4822
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot allows SQL Injection.This issue affects ScadaWatt Otopilot: before 27.05.2025.... Read more
Affected Products :- Published: Jul. 24, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2016-10749
parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a \ character.... Read more
- EPSS Score: %0.57
- Published: Apr. 29, 2019
- Modified: Jul. 22, 2025
-
9.8
CRITICALCVE-2019-11834
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.... Read more
- EPSS Score: %0.62
- Published: May. 09, 2019
- Modified: Jul. 22, 2025
-
9.8
CRITICALCVE-2018-1000217
Dave Gamble cJSON version 1.7.3 and earlier contains a CWE-416: Use After Free vulnerability in cJSON library that can result in Possible crash, corruption of data or even RCE. This attack appear to be exploitable via Depends on how application uses cJSON... Read more
- EPSS Score: %0.51
- Published: Aug. 20, 2018
- Modified: Jul. 22, 2025
-
9.8
CRITICALCVE-2025-7824
A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit h... Read more
Affected Products : jinher_oa- Published: Jul. 19, 2025
- Modified: Aug. 26, 2025
- Vuln Type: XML External Entity
-
9.8
CRITICALCVE-2025-36846
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed dire... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2020-26799
A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-1550
The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules... Read more
Affected Products : keras- Published: Mar. 11, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-7879
A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the file mobileupload.jsp. The manipulation of the argument File leads to unrestricted upload. Th... Read more
Affected Products : metacrm- Published: Jul. 20, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-7921
Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and potentially execute arbitrary code.... Read more
Affected Products :- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-7950
A vulnerability was found in code-projects Public Chat Room 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack may b... Read more
Affected Products : public_chat_room- Published: Jul. 22, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7930
A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /members/add_members.php. The manipulation of the argument mobile leads to sql ... Read more
Affected Products : church_donation_system- Published: Jul. 21, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-26854
A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.... Read more
Affected Products :- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7823
A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation leads to xml external entity reference. The attack can be initiated remotely.... Read more
Affected Products : jinher_oa- Published: Jul. 19, 2025
- Modified: Aug. 26, 2025
- Vuln Type: XML External Entity
-
9.8
CRITICALCVE-2015-10138
The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauth... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-7697
The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verify_field_val... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7696
The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.3 via deserialization of untrusted input within the verify_field_val() f... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-25567
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: the Supplier disputes this because the behavior only enables a local user to attack himself through the UI,... Read more
Affected Products : vpn- Published: Mar. 12, 2025
- Modified: Jul. 19, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-51630
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the function setIpPortFilterRules.... Read more
- Published: Jul. 17, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-52360
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.... Read more
- Published: Nov. 19, 2024
- Modified: Jul. 18, 2025