Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,456
Quick preset (or use dates below)
Clear Filters
Showing 3,541 - 3,560 of 3,615 CVEs
CVE-2024-25182 CRITICAL - 9.8

givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.

Vendor: vvveb
Product: vvvebjs
Published: Dec 29, 2025
Source: NVD
CVE-2024-25181 CRITICAL - 9.1

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" fi...

Vendor: vvveb
Product: vvvebjs
Published: Dec 29, 2025
Source: NVD
CVE-2025-68706 CRITICAL - 9.8

A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attacke...

Vendor: kuwfi
Product: ac900_firmware
Published: Dec 29, 2025
Source: NVD
CVE-2025-15198 CRITICAL - 9.8

A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown processing of the file /login.php. Executing manipulation of the argument User can lead to sql injection. The attack may be launched remotely. The exploit has been made available to th...

Vendor: code-projects
Product: college_notes_uploading_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-15196 CRITICAL - 9.8

A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

Vendor: code-projects
Product: assessment_management
Published: Dec 29, 2025
Source: NVD
CVE-2025-68897 CRITICAL - 9.9

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode allows Code Injection.This issue affects IF AS Shortcode: from n/a through 1.2.

Published: Dec 29, 2025
Source: NVD
CVE-2025-56333 CRITICAL - 9.8

An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component

Vendor: pangolin
Product: pangolin
Published: Dec 29, 2025
Source: NVD
CVE-2025-15195 CRITICAL - 9.8

A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file /admin/add-module.php. This manipulation of the argument linked[] causes sql injection. The attack can be initiated remotely. The exploit has been publicly disc...

Vendor: code-projects
Product: assessment_management
Published: Dec 29, 2025
Source: NVD
CVE-2025-15194 CRITICAL - 9.8

A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality of the file hedwig.cgi of the component HTTP Header Handler. The manipulation of the argument Cookie results in stack-based buffer overflow. It is possible to launch the attack rem...

Vendor: dlink
Product: dir-600_firmware
Published: Dec 29, 2025
Source: NVD
CVE-2025-68929 CRITICAL - 9.0

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution....

Vendor: frappe
Product: frappe
Published: Dec 29, 2025
Source: NVD
CVE-2025-65570 CRITICAL - 9.8

A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array element access as the left-hand operand inside a for-in loop, the instructions implementation leaves an additional array reference on the stack rather tha...

Vendor: jsish
Product: jsish
Published: Dec 29, 2025
Source: NVD
CVE-2025-57460 CRITICAL - 9.8

File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.

Vendor: machsol
Product: machpanel
Published: Dec 29, 2025
Source: NVD
CVE-2025-15186 CRITICAL - 9.8

A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/addusers.php. Such manipulation of the argument a leads to sql injection. It is possible to launch the attack remotely. The exploit has been disc...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-15185 CRITICAL - 9.8

A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /home/refugeesreport.php. This manipulation of the argument a causes sql injection. It is possible to initiate the attack remotely. The exploit has been p...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-15184 CRITICAL - 9.8

A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the file /home/refugeesreport2.php. The manipulation of the argument a results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-15183 CRITICAL - 9.8

A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown function of the file /home/viewtakenfd.php. The manipulation of the argument tfid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been di...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-15182 CRITICAL - 9.8

A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of the file /home/served.php. Executing manipulation of the argument refNo can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the p...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-15181 CRITICAL - 9.8

A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unknown function of the file /home/pagenateRefugeesList.php. Performing manipulation of the argument rfid results in sql injection. Remote exploitation of the attack is possible. The e...

Vendor: fabian
Product: refugee_food_management_system
Published: Dec 29, 2025
Source: NVD
CVE-2025-15228 CRITICAL - 9.8

BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Vendor: welltend
Product: bpmflowwebkit
Published: Dec 29, 2025
Source: NVD
CVE-2025-15226 CRITICAL - 9.8

WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Vendor: sun.net
Product: wmpro
Published: Dec 29, 2025
Source: NVD