| CVE-2024-56829 | CRITICAL | 10.0 | 0.57% | Jan 2, 2025 | Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp |
| CVE-2024-43243 | CRITICAL | 10.0 | 0.53% | Jan 7, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job- |
| CVE-2024-50603 | CRITICAL | 10.0 | 98.55% | Jan 8, 2025 | An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the |
| CVE-2025-22504 | CRITICAL | 10.0 | 0.48% | Jan 9, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in jumpdemand 4ECPS Web Forms 4ecps-we |
| CVE-2024-34166 | CRITICAL | 10.0 | 15.79% | Jan 14, 2025 | An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality |
| CVE-2024-36258 | CRITICAL | 10.0 | 12.45% | Jan 14, 2025 | A stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functio |
| CVE-2024-36290 | CRITICAL | 10.0 | 1.41% | Jan 14, 2025 | A buffer overflow vulnerability exists in the login.cgi Goto_chidx() functionality of Wavlink AC3000 |
| CVE-2024-39608 | CRITICAL | 10.0 | 1.42% | Jan 14, 2025 | A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030. |
| CVE-2024-39754 | CRITICAL | 10.0 | 1.30% | Jan 14, 2025 | A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505 |
| CVE-2024-39759 | CRITICAL | 10.0 | 8.17% | Jan 14, 2025 | Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of |
| CVE-2024-39760 | CRITICAL | 10.0 | 17.38% | Jan 14, 2025 | Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of |
| CVE-2024-39761 | CRITICAL | 10.0 | 8.17% | Jan 14, 2025 | Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of |
| CVE-2025-23922 | CRITICAL | 10.0 | 1.07% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder embed-ispring allows Uploa |
| CVE-2025-21663 | CRITICAL | 10.0 | 0.41% | Jan 21, 2025 | In the Linux kernel, the following vulnerability has been resolved:
net: stmmac: dwmac-tegra: Read |
| CVE-2025-23953 | CRITICAL | 10.0 | 0.66% | Jan 22, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite user files user-files a |
| CVE-2024-55971 | CRITICAL | 10.0 | 0.66% | Jan 23, 2025 | SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.4 |
| CVE-2025-22609 | CRITICAL | 10.0 | 0.75% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. |
| CVE-2025-22612 | CRITICAL | 10.0 | 0.62% | Jan 24, 2025 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. |
| CVE-2024-48841 | CRITICAL | 10.0 | 4.40% | Jan 27, 2025 | Network access can be used to execute arbitrary code with elevated privileges.
This
issue affe |
| CVE-2025-24085 | CRITICAL | 10.0 | 17.65% | Jan 27, 2025 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18. |
| CVE-2025-0982 | CRITICAL | 10.0 | 0.26% | Feb 6, 2025 | Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an acto |
| CVE-2025-24786 | CRITICAL | 10.0 | 2.67% | Feb 6, 2025 | WhoDB is an open source database management tool. While the application only displays Sqlite3 databa |
| CVE-2025-24865 | CRITICAL | 10.0 | 7.11% | Feb 13, 2025 | The administrative web interface of
mySCADA myPRO Manager
can be accessed without authentication
|
| CVE-2024-13152 | CRITICAL | 10.0 | 0.50% | Feb 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i |
| CVE-2025-22654 | CRITICAL | 10.0 | 0.95% | Feb 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allo |