Latest CVE Feed
-
9.8
CRITICALCVE-2024-13085
A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. The manipulation of the argument username leads to sql injection. Th... Read more
Affected Products : land_record_system- Published: Dec. 31, 2024
- Modified: Jan. 06, 2025
-
9.8
CRITICALCVE-2023-47183
Missing Authorization vulnerability in GiveWP GiveWP allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through 2.33.1.... Read more
Affected Products : givewp- Published: Jan. 02, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-55078
An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products :- Published: Jan. 03, 2025
- Modified: Jan. 03, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-0203
A vulnerability was found in code-projects Student Management System 1.0. It has been declared as critical. This vulnerability affects the function showSubject1 of the file /config/DbFunction.php. The manipulation of the argument sid leads to sql injectio... Read more
Affected Products : student_management_system- Published: Jan. 04, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0210
A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument username lea... Read more
Affected Products : school_faculty_scheduling_system- Published: Jan. 04, 2025
- Modified: Jan. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-56273
Missing Authorization vulnerability in WPvivid Backup & Migration WPvivid Backup and Migration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPvivid Backup and Migration: from n/a through 0.9.106.... Read more
Affected Products : migration\,_backup\,_staging- Published: Jan. 07, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-0296
A vulnerability was found in code-projects Online Book Shop 1.0. It has been classified as critical. This affects an unknown part of the file /booklist.php. The manipulation of the argument subcatid leads to sql injection. It is possible to initiate the a... Read more
- Published: Jan. 07, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2022-41573
An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 08, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-13264
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2.... Read more
Affected Products : opigno_module- Published: Jan. 09, 2025
- Modified: Aug. 27, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-54724
PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-57223
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.... Read more
- Published: Jan. 10, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0535
A vulnerability classified as critical has been found in Codezips Gym Management System 1.0. This affects an unknown part of the file /dashboard/admin/edit_mem_submit.php. The manipulation of the argument uid leads to sql injection. It is possible to init... Read more
- Published: Jan. 17, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-57034
WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.... Read more
Affected Products : wegia- Published: Jan. 17, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0562
A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/admin/health_status_entry.php. The manipulation of the argument usrid leads to sql injection. The... Read more
- Published: Jan. 19, 2025
- Modified: Feb. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-32555
Incorrect Privilege Assignment vulnerability in NotFound Easy Real Estate allows Privilege Escalation. This issue affects Easy Real Estate: from n/a through 2.2.6.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-12857
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. This is due to the plugin not properly verifying a user's identity prior to logging them in as that user. This makes it possible for unaut... Read more
Affected Products : adforest- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-0561
A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-pig.php. The manipulation of the argument pigno leads to sql injection. The attack can be initia... Read more
- Published: Jan. 19, 2025
- Modified: Feb. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0637
It has been found that the Beta10 software does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to access private areas and/or areas intended for oth... Read more
Affected Products :- Published: Jan. 23, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-0357
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::handle_image_upload' function in versions up to, and including, 1.6.9. This makes it possible for unauthenti... Read more
- Published: Jan. 25, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-57052
An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.... Read more
Affected Products : youdiancms- Published: Jan. 27, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authentication