Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,698
Quick preset (or use dates below)
Clear Filters
Showing 3,481 - 3,500 of 3,615 CVEs
CVE-2025-15421 CRITICAL - 9.8

A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public...

Vendor: yonyou
Product: ksoa
Published: Jan 02, 2026
Source: NVD
CVE-2025-15420 CRITICAL - 9.8

A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent_work_report.jsp. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The ven...

Vendor: yonyou
Product: ksoa
Published: Jan 02, 2026
Source: NVD
CVE-2025-68620 CRITICAL - 9.1

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior authentication. The attack combines WebSocket-based request enumeration with unauthenticated po...

Vendor: signalk
Product: signal_k_server
Published: Jan 01, 2026
Source: NVD
CVE-2025-15410 CRITICAL - 9.8

A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument L_email leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and...

Vendor: anisha
Product: online_guitar_store
Published: Jan 01, 2026
Source: NVD
CVE-2025-15409 CRITICAL - 9.8

A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executing manipulation of the argument del_pro can lead to sql injection. The attack may be performed from remote. The exploit ha...

Vendor: anisha
Product: online_guitar_store
Published: Jan 01, 2026
Source: NVD
CVE-2025-15408 CRITICAL - 9.8

A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing manipulation of the argument dre_title results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public a...

Vendor: anisha
Product: online_guitar_store
Published: Jan 01, 2026
Source: NVD
CVE-2025-15407 CRITICAL - 9.8

A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Create_category.php. Such manipulation of the argument dre_Ctitle leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and...

Vendor: anisha
Product: online_guitar_store
Published: Jan 01, 2026
Source: NVD
CVE-2026-0544 CRITICAL - 9.8

A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and m...

Vendor: itsourcecode
Product: school_management_system
Published: Jan 01, 2026
Source: NVD
CVE-2025-67707 CRITICAL - 9.8

ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files file, which allows remote attackers to upload arbitrary files.

Vendor: esri
Product: arcgis_server
Published: Dec 31, 2025
Source: NVD
CVE-2025-67706 CRITICAL - 9.8

ArcGIS Server version 11.5 and earlier on Windows and Linux does not properly validate uploaded files file, which allows remote attackers to upload arbitrary files.

Vendor: esri
Product: arcgis_server
Published: Dec 31, 2025
Source: NVD
CVE-2025-69288 CRITICAL - 9.1

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99...

Vendor: kromit
Product: titra
Published: Dec 31, 2025
Source: NVD
CVE-2025-69286 CRITICAL - 9.8

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens ar...

Vendor: infiniflow
Product: ragflow
Published: Dec 31, 2025
Source: NVD
CVE-2025-34468 CRITICAL - 9.8

libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without proper bounds checking. A remote attacker can trigger a crash and potentially a...

Vendor: libcoap
Product: libcoap
Published: Dec 31, 2025
Source: NVD
CVE-2025-15391 CRITICAL - 9.8

A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP Request Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. This vu...

Vendor: dlink
Product: dir-806a_firmware
Published: Dec 31, 2025
Source: NVD
CVE-2025-15114 CRITICAL - 9.8

Ksenia Security Lares 4.0 Home Automation version 1.6 contains a critical security flaw that exposes the alarm system PIN in the 'basisInfo' XML file after authentication. Attackers can retrieve the PIN from the server response to bypass security measures and disable the alarm system witho...

Vendor: kseniasecurity
Product: lares_firmware
Published: Dec 30, 2025
Source: NVD
CVE-2025-15113 CRITICAL - 9.3

Ksenia Security Lares 4.0 Home Automation version 1.6 contains an unprotected endpoint vulnerability that allows authenticated attackers to upload MPFS File System binary images. Attackers can exploit this vulnerability to overwrite flash program memory and potentially execute arbitrary code on the ...

Vendor: kseniasecurity
Product: lares_firmware
Published: Dec 30, 2025
Source: NVD
CVE-2025-15111 CRITICAL - 9.8

Ksenia Security Lares 4.0 Home Automation version 1.6 contains a default credentials vulnerability that allows unauthorized attackers to gain administrative access. Attackers can exploit the weak default administrative credentials to obtain full control of the home automation system.

Vendor: kseniasecurity
Product: lares_firmware
Published: Dec 30, 2025
Source: NVD
CVE-2024-58338 CRITICAL - 10.0

Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and gain full root access to the device by bypassing the restricte...

Vendor: ateme
Product: flamingo_xl_firmware
Published: Dec 30, 2025
Source: NVD
CVE-2023-54327 CRITICAL - 9.8

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and...

Vendor: tinycontrol
Product: lan_controller_firmware
Published: Dec 30, 2025
Source: NVD
CVE-2023-53983 CRITICAL - 9.8

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

Vendor: ateme
Product: flamingo_xl_firmware
Published: Dec 30, 2025
Source: NVD