Latest CVE Feed
-
9.8
CRITICALCVE-2023-31519
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php.... Read more
Affected Products : pharmacy_management_system- EPSS Score: %0.07
- Published: May. 16, 2023
- Modified: Jan. 23, 2025
-
9.8
CRITICALCVE-2024-40754
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.... Read more
Affected Products : escargot- Published: Sep. 10, 2024
- Modified: Sep. 10, 2024
-
9.8
CRITICALCVE-2024-30990
SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.... Read more
Affected Products : client_management_system- Published: Apr. 17, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2025-6794
Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole. Authentication is not required to expl... Read more
Affected Products : qconvergeconsole- Published: Jul. 07, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-1564
The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity through the social login. This makes it possible for unauthenticated attackers to ... Read more
Affected Products :- Published: Mar. 01, 2025
- Modified: Mar. 01, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-1582
A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/all-request.php. The manipulation of the argument viewid leads to sql injection.... Read more
Affected Products : online_nurse_hiring_system- Published: Feb. 23, 2025
- Modified: Feb. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-9982
AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database c... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 15, 2024
-
9.8
CRITICALCVE-2023-26784
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter.... Read more
Affected Products : kirin_fortress_machine- EPSS Score: %0.10
- Published: Mar. 16, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-1852
A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to buffer overflow. T... Read more
- Published: Mar. 03, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1872
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php.... Read more
Affected Products : best_online_news_portal- Published: Mar. 03, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-0177
The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthent... Read more
Affected Products : javo_core- Published: Mar. 08, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-7517
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /getDay.php. The manipulation of the argument cidval leads to sql injection. T... Read more
Affected Products : online_appointment_booking_system- Published: Jul. 13, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-8969
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/approve_user.php. The manipulation of the argument ID leads to sql injection. The attack m... Read more
Affected Products : online_tour_\&_travel_management_system- Published: Aug. 14, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-0268
A vulnerability, which was classified as critical, has been found in Kashipara Hospital Management System up to 1.0. Affected by this issue is some unknown functionality of the file registration.php. The manipulation of the argument name/email/pass/gender... Read more
Affected Products : hospital_management_system- EPSS Score: %0.18
- Published: Jan. 07, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28037
An issue was discovered in the internment crate before 0.4.2 for Rust. There is a data race that can cause memory corruption because of the unconditional implementation of Sync for Intern<T>.... Read more
Affected Products : internment- EPSS Score: %0.42
- Published: Mar. 05, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-0294
A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to os command inject... Read more
- EPSS Score: %2.07
- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2025-0536
A vulnerability classified as critical was found in 1000 Projects Attendance Tracking Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_action.php. The manipulation of the argument attendance_id leads to sql injection.... Read more
Affected Products : attendance_tracking_management_system- Published: Jan. 17, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-20681
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416936; ... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-3968
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.... Read more
Affected Products : imanager- Published: May. 15, 2024
- Modified: Jan. 21, 2025
-
9.8
CRITICALCVE-2025-0767
WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php.... Read more
Affected Products : wp_activity_log- Published: Feb. 27, 2025
- Modified: May. 21, 2025
- Vuln Type: Information Disclosure