Latest CVE Feed
-
9.8
CRITICALCVE-2024-4815
A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240506. Affected by this issue is some unknown functionality of the file /view/bugSolve/viewData/detail.php. The manipulation of the argument filename leads to os c... Read more
Affected Products : rg-uac_firmware rg-uac_6000-e50_firmware rg-uac rg-uac_6000-e50 rg-uac_6000-cc_firmware rg-uac_6000-cc rg-uac_6000-e10_firmware rg-uac_6000-e10 rg-uac_6000-e10c_firmware rg-uac_6000-e10c +46 more products- Published: May. 14, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-55031
Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range could have used this to trick the user into using their passkey to log the attacker's computer into the ta... Read more
- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-4814
A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240506. Affected by this vulnerability is an unknown functionality of the file /view/networkConfig/RouteConfig/StaticRoute/static_route_edit_commit.php. The manipulation of the argu... Read more
Affected Products : rg-uac_firmware rg-uac_6000-e50_firmware rg-uac rg-uac_6000-e50 rg-uac_6000-cc_firmware rg-uac_6000-cc rg-uac_6000-e10_firmware rg-uac_6000-e10 rg-uac_6000-e10c_firmware rg-uac_6000-e10c +46 more products- Published: May. 14, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-4813
A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240506. Affected is an unknown function of the file /view/networkConfig/physicalInterface/interface_commit.php. The manipulation of the argument name leads to os command inject... Read more
Affected Products : rg-uac_firmware rg-uac_6000-e50_firmware rg-uac rg-uac_6000-e50 rg-uac_6000-cc_firmware rg-uac_6000-cc rg-uac_6000-e10_firmware rg-uac_6000-e10 rg-uac_6000-e10c_firmware rg-uac_6000-e10c +46 more products- Published: May. 14, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2023-40146
A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with... Read more
- Published: Apr. 17, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2023-49134
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link N300 Wireless Access Point (EAP115 V4) v5.0.4 Build 20220216. A spec... Read more
- Published: Apr. 09, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2023-49133
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926 and Tp-Link N300 Wireless Access Point (EAP115 V4) v5.0.4 Build 20220216. A spec... Read more
- Published: Apr. 09, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-13022
A vulnerability, which was classified as critical, was found in taisan tarzan-cms 1.0.0. This affects the function UploadResponse of the file src/main/java/com/tarzan/cms/modules/admin/controller/common/UploadController.java of the component Article Manag... Read more
Affected Products : tarzan-cms- Published: Dec. 29, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-57754
eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control... Read more
Affected Products :- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-9307
A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/session.php. This manipulation of the argument sesssion causes sql injection. The attack can be initiated remotely. The exploit has bee... Read more
Affected Products : online_course_registration- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9305
A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is an unknown function of the file /bank/mnotice.php. The manipulation of the argument ID leads to sql injection. It is possible to initia... Read more
Affected Products : online_bank_management_system- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-3737
A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery of the file /adminPage/www/addOver. The manipulation of the argument dir leads to path traversal. The attac... Read more
Affected Products : nginxwebui- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2025-9296
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the ... Read more
Affected Products : emlog- Published: Aug. 21, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-8913
Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.... Read more
Affected Products : organization_portal_system- Published: Aug. 13, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-6187
A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/vpn/autovpn/sub_commit.php. The manipulation of the argument key leads to os command injection. The attack can be ini... Read more
- Published: Jun. 20, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-6186
A vulnerability, which was classified as critical, was found in Ruijie RG-UAC 1.0. This affects an unknown part of the file /view/userAuthentication/SSO/commit.php. The manipulation of the argument ad_log_name leads to os command injection. It is possible... Read more
- Published: Jun. 20, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-6184
A vulnerability classified as critical was found in Ruijie RG-UAC 1.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/reboot/reboot_commit.php. The manipulation of the argument servicename leads to os command inj... Read more
- Published: Jun. 20, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-31011
Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.... Read more
Affected Products : beescms- Published: Apr. 03, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-3739
A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown code of the file /adminPage/main/upload. The manipulation of the argument file leads to os command injection. The attack can be initiate... Read more
Affected Products : nginxwebui- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025
-
9.8
CRITICALCVE-2024-3738
A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation of the argument nginxPath leads to improper certificate validation. It is p... Read more
- Published: Apr. 13, 2024
- Modified: Aug. 21, 2025