Latest CVE Feed
-
9.8
CRITICALCVE-2025-8610
AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to ex... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 25, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-57157
Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-54143
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141.... Read more
Affected Products : firefox- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-40535
Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the config_3g_para function.... Read more
- Published: Jul. 16, 2024
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2025-9156
A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/sports.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is ... Read more
Affected Products : sports_management_system- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-44373
A Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php.... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-55306
GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could ... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-24322
An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lead to arbitrary code execution. An attacker can browse to the device to trig... Read more
- Published: Aug. 20, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-5765
The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection... Read more
- Published: Jul. 30, 2024
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2025-5497
A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_feedimport/inc/processing.inc.php of the component Feedimport Module. Performing manipulation of the argum... Read more
Affected Products : phpwcms- Published: Jun. 03, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54014
Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic allows Object Injection. This issue affects MediCenter - Health Medical Clinic: from n/a through 15.1.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9155
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forget_password.php. Such manipulation of the argument email leads to sql injection. The attack may be launched ... Read more
Affected Products : online_tour_\&_travel_management_system- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-9154
A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page-login.php. This manipulation of the argument email causes sql injection. The attack may be initiated remo... Read more
Affected Products : online_tour_\&_travel_management_system- Published: Aug. 19, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-53580
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro allows Privilege Escalation. This issue affects Simple Business Directory Pro: from n/a through n/a.... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
-
9.8
CRITICALCVE-2025-55444
A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code executi... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-27540
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'Authenticate' method. This could allow an unauthenticated remote attacker to by... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-54336
In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an attacker can login with any other string that evaluates to 0.0 (such as the 0e0 string). This occurs in adm... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-27495
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an unauthenticated remote attacker to byp... Read more
Affected Products : telecontrol_server_basic- Published: Apr. 16, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8723
The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in all versions up to, and including, 1.5.6. This makes it pos... Read more
Affected Products :- Published: Aug. 19, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-9053
A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of the file /updatesubcategory.php. The manipulation of the argument t1/s1 leads to sql injection. The attack can be initiated remotely. ... Read more
- Published: Aug. 15, 2025
- Modified: Aug. 21, 2025
- Vuln Type: Injection