Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,149
Quick preset (or use dates below)
Clear Filters
Showing 3,581 - 3,600 of 3,615 CVEs
CVE-2025-15077 CRITICAL - 9.8

A security vulnerability has been detected in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /form137.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly an...

Vendor: angeljudesuarez
Product: student_management_system
Published: Dec 25, 2025
Source: NVD
CVE-2025-15075 CRITICAL - 9.8

A security flaw has been discovered in itsourcecode Student Management System 1.0. This issue affects some unknown processing of the file /student_p.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the pu...

Vendor: angeljudesuarez
Product: student_management_system
Published: Dec 25, 2025
Source: NVD
CVE-2025-15074 CRITICAL - 9.8

A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /customer_details.php. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be us...

Vendor: itsourcecode
Product: online_frozen_foods_ordering_system
Published: Dec 25, 2025
Source: NVD
CVE-2025-15073 CRITICAL - 9.8

A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and m...

Vendor: itsourcecode
Product: online_frozen_foods_ordering_system
Published: Dec 24, 2025
Source: NVD
CVE-2025-8769 CRITICAL - 9.8

Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server.

Published: Dec 24, 2025
Source: NVD
CVE-2019-25249 CRITICAL - 9.8

devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating syste...

Published: Dec 24, 2025
Source: NVD
CVE-2019-25241 CRITICAL - 9.8

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

Vendor: iwt
Product: facesentry_access_control_system_firmware
Published: Dec 24, 2025
Source: NVD
CVE-2019-25240 CRITICAL - 9.8

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.

Published: Dec 24, 2025
Source: NVD
CVE-2019-25237 CRITICAL - 9.8

V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to intege...

Published: Dec 24, 2025
Source: NVD
CVE-2019-25236 CRITICAL - 9.8

iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get_jpeg endpoint without authentication.

Published: Dec 24, 2025
Source: NVD
CVE-2019-25235 CRITICAL - 9.8

Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system in...

Published: Dec 24, 2025
Source: NVD
CVE-2018-25154 CRITICAL - 9.8

GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.

Published: Dec 24, 2025
Source: NVD
CVE-2018-25142 CRITICAL - 9.8

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

Published: Dec 24, 2025
Source: NVD
CVE-2018-25138 CRITICAL - 9.8

FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to multiple camera interfaces using predefined username and passwo...

Vendor: flir
Product: flir_ax8_firmware
Published: Dec 24, 2025
Source: NVD
CVE-2018-25135 CRITICAL - 9.8

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or 'Position' to trigger Excel macr...

Published: Dec 24, 2025
Source: NVD
CVE-2018-25134 CRITICAL - 9.8

Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attackers to create admin user accounts. Attackers can exploit the missing control check by sending crafted POST requests to create administrative accounts a...

Published: Dec 24, 2025
Source: NVD
CVE-2025-68600 CRITICAL - 9.1

Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.4.

Published: Dec 24, 2025
Source: NVD
CVE-2025-68590 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Blind SQL Injection.This issue affects Integration for Contact Form 7 HubSpot: from n/a through <= 1.4.2.

Published: Dec 24, 2025
Source: NVD
CVE-2025-68570 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate Sync: from n/a through <= 3.2.2.

Published: Dec 24, 2025
Source: NVD
CVE-2025-68565 CRITICAL - 9.8

Missing Authorization vulnerability in JayBee Twitch Player ttv-easy-embed-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Twitch Player: from n/a through <= 2.1.3.

Published: Dec 24, 2025
Source: NVD