Latest CVE Feed
-
10.0
CRITICALCVE-2025-26606
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `informacao_adicional.php` endpoint. This vulnerability could allow an attacker to execu... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
-
10.0
CRITICALCVE-2025-26612
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `adicionar_almoxarife.php` endpoint. This vulnerability could allow an attacker to execu... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
-
10.0
CRITICALCVE-2025-26617
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `historico_paciente.php` endpoint. This vulnerability could allow an attacker to execute... Read more
Affected Products : wegia- Published: Feb. 18, 2025
- Modified: Feb. 28, 2025
-
10.0
CRITICALCVE-2025-26776
Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3.... Read more
Affected Products :- Published: Feb. 22, 2025
- Modified: Feb. 22, 2025
-
10.0
CRITICALCVE-2023-25574
`jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI). LTI13Authenticator that was introduced in `jupyterhub-ltiauthenticator` 1.3.0 wasn't validating JWT signatures. This is believed to allow the LTI13Authe... Read more
Affected Products :- Published: Feb. 25, 2025
- Modified: Feb. 25, 2025
-
10.0
CRITICALCVE-2024-50704
Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via a specially crafted HTTP POST request.... Read more
Affected Products : tripleplay- Published: Mar. 04, 2025
- Modified: May. 28, 2025
-
10.0
CRITICALCVE-2025-26701
An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.... Read more
Affected Products : monitoring_and_management- Published: Mar. 11, 2025
- Modified: Mar. 11, 2025
-
10.0
CRITICALCVE-2024-12909
A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arb... Read more
Affected Products : llamaindex- Published: Mar. 20, 2025
- Modified: Jul. 30, 2025
-
10.0
CRITICALCVE-2025-26853
DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.... Read more
- Published: Mar. 20, 2025
- Modified: Apr. 23, 2025
-
10.0
CRITICALCVE-2021-47667
An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping off a file via a ... Read more
Affected Products : zendto- Published: Apr. 05, 2025
- Modified: Apr. 07, 2025
-
10.0
CRITICALCVE-2025-32660
Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager allows Upload a Web Shell to a Web Server. This issue affects JS Job Manager: from n/a through 2.0.2.... Read more
Affected Products : js_job_manager- Published: Apr. 17, 2025
- Modified: Apr. 17, 2025
-
10.0
CRITICALCVE-2025-46348
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could create and downl... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
-
10.0
CRITICALCVE-2025-0505
On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state... Read more
Affected Products : cloudvision_portal- Published: May. 08, 2025
- Modified: May. 12, 2025
-
10.0
CRITICALCVE-2025-29813
[Spoofable identity claims] Authentication Bypass by Assumed-Immutable Data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_devops- Published: May. 08, 2025
- Modified: Jun. 05, 2025
-
10.0
CRITICALCVE-2025-26389
A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanitize the input parameters required for the `exportDiagramPage` endpoint. This could allow an unauthenticate... Read more
- Published: May. 13, 2025
- Modified: May. 13, 2025
-
10.0
CRITICALCVE-2023-6977
This vulnerability enables malicious users to read sensitive files on the server.... Read more
Affected Products : mlflow- EPSS Score: %85.80
- Published: Dec. 20, 2023
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-48418
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb before SUW completion due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges n... Read more
- EPSS Score: %0.06
- Published: Jan. 02, 2024
- Modified: Feb. 13, 2025
-
10.0
CRITICALCVE-2023-49617
The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication. ... Read more
- EPSS Score: %0.16
- Published: Feb. 01, 2024
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-47143
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerabl... Read more
Affected Products : tivoli_application_dependency_discovery_manager- EPSS Score: %0.10
- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-27767
CWE-287: Improper Authentication may allow Authentication Bypass ... Read more
Affected Products : unilogic- Published: Mar. 18, 2024
- Modified: Mar. 10, 2025