Latest CVE Feed
-
9.8
CRITICALCVE-2021-30188
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.... Read more
Affected Products : 750-831_firmware 750-852_firmware 750-880_firmware 750-881_firmware 750-889_firmware 750-829_firmware 750-882_firmware 750-885_firmware plcwinnt 750-891_firmware +46 more products- Published: May. 25, 2021
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2025-8926
A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack can be laun... Read more
- Published: Aug. 13, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-55150
Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, when using the /api/v1/convert/html/pdf endpoint to convert HTML to PDF, the backend calls a third-party tool to process it and include... Read more
Affected Products : stirling_pdf- Published: Aug. 11, 2025
- Modified: Aug. 15, 2025
-
9.8
CRITICALCVE-2025-8932
A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of the argument ssalescat leads to sql injection. The attack can be initiated re... Read more
Affected Products : sales_management_system- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-51390
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig function.... Read more
- Published: Aug. 04, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9022
A vulnerability was identified in SourceCodester Online Bank Management System up to 1.0. This issue affects some unknown processing of the file /bank/statements.php. The manipulation of the argument email leads to sql injection. The attack may be initiat... Read more
Affected Products : online_bank_management_system- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-7778
The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it possible for unau... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-6679
The Bit Form builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 2.20.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affec... Read more
Affected Products :- Published: Aug. 15, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2017-3907
Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified ... Read more
Affected Products : mcafee_threat_intelligence_exchange- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9819
The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication.... Read more
Affected Products : bharat_interface_for_money_\(bhim\)- Published: Aug. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2000-1218
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to po... Read more
- Published: Apr. 14, 2000
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2023-43453
An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.... Read more
- Published: Dec. 01, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-34388
An Improper Authentication vulnerability in the Schweitzer Engineering Laboratories SEL-451 could allow a remote unauthenticated attacker to potentially perform session hijacking attack and bypass authentication. See product Instruction Manual Appendix... Read more
- Published: Nov. 30, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2004-2214
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.... Read more
Affected Products : appweb_http_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2024-6253
A vulnerability was found in itsourcecode Online Food Ordering System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /purchase.php. The manipulation of the argument customer leads to sql injection. The att... Read more
Affected Products : online_food_ordering_system- Published: Jun. 22, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-2363
A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. This issue affects some unknown processing of the file view_room.php. The manipulation of the argument id leads to sql injection. The attack... Read more
- Published: Apr. 28, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-3435
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.... Read more
Affected Products : newsworld- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2006-5610
PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : fully_modded_phpbb- Published: Oct. 31, 2006
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2007-0681
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.... Read more
Affected Products : extcalendar- Published: Feb. 03, 2007
- Modified: Apr. 09, 2025
-
9.8
CRITICALCVE-2023-43548
Memory corruption while parsing qcp clip with invalid chunk data size.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6391_firmware qca6420_firmware qca6430_firmware qca6574au_firmware qca6595au_firmware qca6696_firmware sa6145p_firmware sa6150p_firmware +305 more products- Published: Mar. 04, 2024
- Modified: Aug. 11, 2025