Latest CVE Feed
-
9.8
CRITICALCVE-2024-4814
A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240506. Affected by this vulnerability is an unknown functionality of the file /view/networkConfig/RouteConfig/StaticRoute/static_route_edit_commit.php. The manipulation of the argu... Read more
Affected Products : rg-uac_firmware rg-uac_6000-e50_firmware rg-uac rg-uac_6000-e50 rg-uac_6000-cc_firmware rg-uac_6000-cc rg-uac_6000-e10_firmware rg-uac_6000-e10 rg-uac_6000-e10c_firmware rg-uac_6000-e10c +46 more products- Published: May. 14, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-4813
A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240506. Affected is an unknown function of the file /view/networkConfig/physicalInterface/interface_commit.php. The manipulation of the argument name leads to os command inject... Read more
Affected Products : rg-uac_firmware rg-uac_6000-e50_firmware rg-uac rg-uac_6000-e50 rg-uac_6000-cc_firmware rg-uac_6000-cc rg-uac_6000-e10_firmware rg-uac_6000-e10 rg-uac_6000-e10c_firmware rg-uac_6000-e10c +46 more products- Published: May. 14, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2023-40146
A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with... Read more
- Published: Apr. 17, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2023-49134
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link N300 Wireless Access Point (EAP115 V4) v5.0.4 Build 20220216. A spec... Read more
- Published: Apr. 09, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2023-49133
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link N300 Wireless Access Point (EAP115 V4) v5.0.4 Build 20220216. A spec... Read more
- Published: Apr. 09, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-13022
A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function UploadResponse of the file src/main/java/com/tarzan/cms/modules/admin/controller/common/UploadController.java of the component Article Manag... Read more
Affected Products : tarzan-cms- Published: Dec. 29, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-57754
eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-9307
A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/session.php. This manipulation of the argument sesssion causes sql injection. The attack can be initiated remotely. The exploit has bee... Read more
Affected Products : online_course_registration- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9305
A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is an unknown function of the file /bank/mnotice.php. The manipulation of the argument ID leads to sql injection. It is possible to initia... Read more
Affected Products : online_bank_management_system- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-3737
A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery of the file /adminPage/www/addOver. The manipulation of the argument dir leads to path traversal. The attac... Read more
Affected Products : nginxwebui- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-9296
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the ... Read more
Affected Products : emlog- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8913
Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.... Read more
Affected Products : organization_portal_system- Published: Aug. 13, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-6187
A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/vpn/autovpn/sub_commit.php. The manipulation of the argument key leads to os command injection. The attack can be ini... Read more
- Published: Jun. 20, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-6186
A vulnerability, which was classified as critical, was found in Ruijie RG-UAC 1.0. This affects an unknown part of the file /view/userAuthentication/SSO/commit.php. The manipulation of the argument ad_log_name leads to os command injection. It is possible... Read more
- Published: Jun. 20, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-6184
A vulnerability classified as critical was found in Ruijie RG-UAC 1.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/reboot/reboot_commit.php. The manipulation of the argument servicename leads to os command inj... Read more
- Published: Jun. 20, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-31011
Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.... Read more
Affected Products : beescms- Published: Apr. 03, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-3739
A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown code of the file /adminPage/main/upload. The manipulation of the argument file leads to os command injection. The attack can be initiate... Read more
Affected Products : nginxwebui- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-3738
A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation of the argument nginxPath leads to improper certificate validation. It is p... Read more
- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-57154
Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-51543
An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password endpoint.... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Authentication