Latest CVE Feed
-
9.8
CRITICALCVE-2025-15409
A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executing manipulation of the argument del_pro can lead to sql injection. The attack... Read more
Affected Products : online_guitar_store- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
6.2
MEDIUMCVE-2025-68950
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any sit... Read more
Affected Products : imagemagick- Published: Dec. 30, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-15410
A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument L_email leads to sql injection. It is possible to initiate the attack re... Read more
Affected Products : online_guitar_store- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-69204
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered ... Read more
Affected Products : imagemagick- Published: Dec. 30, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-68700
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host process via the frontend Canvas CodeExe... Read more
Affected Products : ragflow- Published: Dec. 31, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-68273
Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data sch... Read more
Affected Products : signal_k_server- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2025-68619
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the endpoint validates that the package name e... Read more
Affected Products : signal_k_server- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Supply Chain
-
9.1
CRITICALCVE-2025-68620
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior authentication. The attack combines WebSocket-base... Read more
Affected Products : signal_k_server- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-69203
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the access request system have two related features that when combined by themselves and with an information disclosure vulnerability enable convinci... Read more
Affected Products : signal_k_server- Published: Jan. 01, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-15420
A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has bee... Read more
Affected Products : ksoa- Published: Jan. 02, 2026
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-67109
Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.... Read more
Affected Products : cyclone_data_distribution_service- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-67111
An integer overflow in the RTPS protocol implementation of OpenDDS DDS before v3.33.0 allows attackers to cause a Denial of Service (DoS) via a crafted message.... Read more
Affected Products : opendds- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
10.0
CRITICALCVE-2024-57521
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.... Read more
Affected Products : ruoyi- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29228
Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.... Read more
- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-29229
linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.... Read more
- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
6.2
MEDIUMCVE-2025-65410
A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter.... Read more
Affected Products : unrtf- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Denial of Service
-
4.0
MEDIUMCVE-2025-65713
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.... Read more
Affected Products : home-assistant- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-51511
Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.... Read more
Affected Products : cadmium_cms- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Misconfiguration
-
8.4
HIGHCVE-2025-25364
A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges.... Read more
Affected Products : speedify- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-65354
Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the sitem_name POST parameter. Crafted payloads can alter query logic and disclose database contents. Exploitation may result in... Read more
Affected Products : event_management- Published: Dec. 23, 2025
- Modified: Jan. 06, 2026
- Vuln Type: Injection