Latest CVE Feed
-
9.8
CRITICALCVE-2025-29306
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.... Read more
Affected Products : foxcms- Published: Mar. 27, 2025
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2024-49601
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, lead... Read more
Affected Products : unity_operating_environment- Published: Mar. 28, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-30372
Emlog is an open source website building system. Emlog Pro versions pro-2.5.7 and pro-2.5.8 contain an SQL injection vulnerability. `search_controller.php` does not use addslashes after urldecode, allowing the preceeding addslashes to be bypassed by URL d... Read more
Affected Products : emlog- Published: Mar. 28, 2025
- Modified: Apr. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-24292
A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function in the aim.js component.... Read more
Affected Products : software_development_kit- Published: Mar. 28, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-25579
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.... Read more
- Published: Mar. 28, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-13804
Unauthenticated RCE in HPE Insight Cluster Management Utility... Read more
Affected Products :- Published: Mar. 30, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-26683
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.... Read more
Affected Products : azure_playwright- Published: Mar. 31, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-31095
Authentication Bypass Using an Alternate Path or Channel vulnerability in ho3einie Material Dashboard allows Authentication Bypass. This issue affects Material Dashboard: from n/a through 1.4.5.... Read more
Affected Products :- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-2005
The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the file uploads field of the registration form in all versions up to, and including, 3.2.32. This makes it possible for unauthenticate... Read more
Affected Products : front_end_users- Published: Apr. 02, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-29063
An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter passed to /goform/set_hidessid_cfg is not handled properly.... Read more
- Published: Apr. 02, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3168
A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php. The manipulation of the argument editid leads to sql i... Read more
Affected Products : time_table_generator_system- Published: Apr. 03, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3171
A vulnerability classified as critical was found in Project Worlds Online Lawyer Management System 1.0. This vulnerability affects unknown code of the file /approve_lawyer.php. The manipulation of the argument unblock_id leads to sql injection. The attack... Read more
- Published: Apr. 03, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-22611
OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.... Read more
Affected Products : openemr- Published: Apr. 03, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3180
A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor/deleteschedule.php. The manipulation of the argument ID leads to... Read more
Affected Products : doctor_appointment_system online_doctor_appointment_booking_system_php_and_mysql- Published: Apr. 03, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3182
A vulnerability, which was classified as critical, was found in projectworlds Online Doctor Appointment Booking System 1.0. This affects an unknown part of the file /patient/getschedule.php. The manipulation of the argument q leads to sql injection. It is... Read more
Affected Products : doctor_appointment_system online_doctor_appointment_booking_system_php_and_mysql- Published: Apr. 03, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-3184
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /patient/profile.php?patientId=1. The manipulation of the argument patientFirstName ... Read more
Affected Products : doctor_appointment_system online_doctor_appointment_booking_system_php_and_mysql- Published: Apr. 03, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-27520
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. A Remote Code Execution (RCE) vulnerability caused by insecure deserialization has been identified in the latest version (v1.4.2) of BentoML. It all... Read more
Affected Products : bentoml- Published: Apr. 04, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2023-40629
SQLi vulnerability in LMS Lite component for Joomla.... Read more
Affected Products : lms_king_lite- EPSS Score: %0.73
- Published: Dec. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-40630
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.... Read more
Affected Products : jcdashboard- EPSS Score: %0.28
- Published: Dec. 14, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-3352
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-scdetails.php. The manipulation of the argument contnum leads to sql inject... Read more
Affected Products : old_age_home_management_system- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection