Latest CVE Feed
-
9.8
CRITICALCVE-2024-53438
EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing ... Read more
Affected Products : churchcrm- Published: Nov. 22, 2024
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2025-27641
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.951 Application 20.0.2368 allows Unauthenticated APIs for Single-Sign On V-2024-009.... Read more
- Published: Mar. 05, 2025
- Modified: Apr. 15, 2025
-
9.8
CRITICALCVE-2023-24350
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.... Read more
- EPSS Score: %2.08
- Published: Feb. 10, 2023
- Modified: Mar. 24, 2025
-
9.8
CRITICALCVE-2023-26323
A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.... Read more
Affected Products : app_market- Published: Aug. 28, 2024
- Modified: Mar. 27, 2025
-
9.8
CRITICALCVE-2024-8999
lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnerability allows any user to export the entire database data by creating a stream to Google BigQuery without ... Read more
Affected Products : lunary- Published: Mar. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-8502
A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the AgentServerServicer.create_agent method, whe... Read more
Affected Products : agentscope- Published: Mar. 20, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-31049
Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-48175
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.... Read more
Affected Products : rukovoditel- EPSS Score: %5.23
- Published: Jan. 30, 2023
- Modified: Mar. 28, 2025
-
9.8
CRITICALCVE-2023-24762
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.... Read more
- EPSS Score: %1.70
- Published: Mar. 13, 2023
- Modified: Mar. 03, 2025
-
9.8
CRITICALCVE-2024-8262
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.This issue affects OBS: before 24.0927.... Read more
Affected Products : student_affairs_information_system- Published: Mar. 03, 2025
- Modified: Mar. 10, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-33403
A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.... Read more
Affected Products : complete_web-based_school_management_system- Published: May. 06, 2024
- Modified: Mar. 25, 2025
-
9.8
CRITICALCVE-2024-4267
A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of special elements used in a command within the 'open_file' ... Read more
- Published: May. 22, 2024
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2021-30193
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.... Read more
Affected Products : 750-831_firmware 750-852_firmware 750-880_firmware 750-881_firmware 750-889_firmware 750-829_firmware 750-882_firmware 750-885_firmware 750-891_firmware 750-823_firmware +45 more products- EPSS Score: %0.53
- Published: May. 25, 2021
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2021-30189
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.... Read more
Affected Products : 750-831_firmware 750-852_firmware 750-880_firmware 750-881_firmware 750-889_firmware 750-829_firmware 750-882_firmware 750-885_firmware 750-891_firmware 750-823_firmware +45 more products- EPSS Score: %0.57
- Published: May. 25, 2021
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2021-30188
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.... Read more
Affected Products : 750-831_firmware 750-852_firmware 750-880_firmware 750-881_firmware 750-889_firmware 750-829_firmware 750-882_firmware 750-885_firmware plcwinnt 750-891_firmware +46 more products- EPSS Score: %0.57
- Published: May. 25, 2021
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2025-8926
A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be laun... Read more
- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-55150
Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and include... Read more
Affected Products : stirling_pdf- Published: Aug. 11, 2025
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2025-8932
A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated re... Read more
Affected Products : sales_management_system- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-51390
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.... Read more
- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9022
A vulnerability was identified in SourceCodester Online Bank Management System up to 1.0. This issue affects some unknown processing of the file /bank/statements.php. The manipulation of the argument email leads to sql injection. The attack may be initiat... Read more
Affected Products : online_bank_management_system- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection