Latest CVE Feed
-
9.8
CRITICALCVE-2025-46189
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.... Read more
Affected Products : client_database_management_system- Published: May. 09, 2025
- Modified: May. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-46188
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.... Read more
Affected Products : client_database_management_system- Published: May. 09, 2025
- Modified: May. 22, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45513
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.... Read more
- Published: May. 09, 2025
- Modified: May. 24, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-28203
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.... Read more
- Published: May. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-28202
Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.... Read more
- Published: May. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication
-
6.8
MEDIUMCVE-2025-28201
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.... Read more
- Published: May. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-28200
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.... Read more
- Published: May. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2024-9524
Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime Version 1.1.96.2 on Windows 10 x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Race Condition
-
7.8
HIGHCVE-2024-13962
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM... Read more
Affected Products : cleanup_premium- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Race Condition
-
7.8
HIGHCVE-2024-13961
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a s... Read more
Affected Products : cleanup_premium- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Race Condition
-
7.8
HIGHCVE-2024-13960
Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Race Condition
-
7.8
HIGHCVE-2024-13959
Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-13944
Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via ... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-13759
Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64 allows local attackers to gain system-level privileges via arbitrary file deletion... Read more
Affected Products : avira_prime- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-45887
Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.... Read more
Affected Products : yifang- Published: May. 09, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-45885
PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.... Read more
Affected Products : vehicle_parking_management_system- Published: May. 09, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-12442
EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-11861
EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.... Read more
Affected Products :- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Injection
-
5.9
MEDIUMCVE-2025-4382
A flaw was found in systems utilizing LUKS-encrypted disks with GRUB configured for TPM-based auto-decryption. When GRUB is set to automatically decrypt disks using keys stored in the TPM, it reads the decryption key into system memory. If an attacker wit... Read more
Affected Products : grub2- Published: May. 09, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-4206
The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'process_export_delete' and 'process_import_delete' fun... Read more
Affected Products : groundhogg- Published: May. 09, 2025
- Modified: May. 12, 2025
- Vuln Type: Path Traversal