Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.9

    CRITICAL
    CVE-2025-66209

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/servic... Read more

    Affected Products : coolify
    • Published: Dec. 23, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
  • 7.8

    HIGH
    CVE-2025-14414

    Soda PDF Desktop Word File Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Soda PDF Desktop. User interaction is required to exploit this vulner... Read more

    Affected Products : soda_pdf_desktop
    • Published: Dec. 23, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Information Disclosure
  • 7.8

    HIGH
    CVE-2025-14413

    Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Soda PDF Desktop. User interaction is required to exploit this vul... Read more

    Affected Products : soda_pdf_desktop
    • Published: Dec. 23, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Path Traversal
  • 9.1

    CRITICAL
    CVE-2025-56332

    Authentication Bypass in fosrl/pangolin v1.6.2 and before allows attackers to access Pangolin resource via Insecure Default Configuration... Read more

    Affected Products : pangolin
    • Published: Dec. 30, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Authentication
  • 9.8

    CRITICAL
    CVE-2025-56333

    An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component... Read more

    Affected Products : pangolin
    • Published: Dec. 29, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Authentication
  • 5.3

    MEDIUM
    CVE-2025-15118

    A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of the file /member/address/update/ of the component Member Endpoint. The manipulation leads to improper authorization. Remote exploitation ... Read more

    Affected Products : mall
    • Published: Dec. 28, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Authorization
  • 9.8

    CRITICAL
    CVE-2025-15208

    A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/editrefugee.php. The manipulation of the argument rfid results in sql injection. The attack can... Read more

    Affected Products : refugee_food_management_system
    • Published: Dec. 29, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-15207

    A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument chkId[] leads to sql injection. It is possible to initiate the attack remote... Read more

    Affected Products : supplier_management_system
    • Published: Dec. 29, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-15206

    A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/add_area.php. Executing manipulation of the argument txtAreaCode can lead to sql injection. The attack may be performed from remote. The... Read more

    Affected Products : supplier_management_system
    • Published: Dec. 29, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
  • 7.2

    HIGH
    CVE-2025-15197

    A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted... Read more

    • Published: Dec. 29, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Misconfiguration
  • 9.8

    CRITICAL
    CVE-2025-15196

    A vulnerability was identified in code-projects Assessment Management 1.0. This affects an unknown part of the file login.php. Such manipulation of the argument userid leads to sql injection. The attack can be launched remotely. The exploit is publicly av... Read more

    Affected Products : assessment_management
    • Published: Dec. 29, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-15195

    A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file /admin/add-module.php. This manipulation of the argument linked[] causes sql injection. The attack can be initiated... Read more

    Affected Products : assessment_management
    • Published: Dec. 29, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-68696

    httparty is an API tool. In versions 0.23.2 and prior, httparty is vulnerable to SSRF. This issue can pose a risk of leaking API keys, and it can also allow third parties to issue requests to internal servers. This issue has been patched via commit 0529bc... Read more

    Affected Products : httparty httparty
    • Published: Dec. 23, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Server-Side Request Forgery
  • 5.8

    MEDIUM
    CVE-2025-8075

    Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format request messages is inadequate. This vulnerability could allow an att... Read more

    • Published: Dec. 26, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Cross-Site Scripting
  • 7.8

    HIGH
    CVE-2025-52601

    Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in Device Manager that a hardcoded encryption key for sensitive information. An attacker can... Read more

    • Published: Dec. 26, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Cryptography
  • 7.2

    HIGH
    CVE-2025-52600

    Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered a vulnerability in camera video analytics that Improper input validation. This vulnerability could allow an ... Read more

    • Published: Dec. 26, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
  • 6.5

    MEDIUM
    CVE-2025-52599

    Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered Inadequate of permission management for camera guest account. The manufacturer has released patch firmware f... Read more

    • Published: Dec. 26, 2025
    • Modified: Jan. 07, 2026
    • Vuln Type: Authorization
  • 9.8

    CRITICAL
    CVE-2025-15436

    A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /worksheet/work_edit.jsp. Such manipulation of the argument Report leads to sql injection. The attack can be launched remotely. The exploit... Read more

    Affected Products : ksoa
    • Published: Jan. 02, 2026
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-15435

    A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_update.jsp. This manipulation of the argument Report causes sql injection. The attack can be initiated remotely. The exploit h... Read more

    Affected Products : ksoa
    • Published: Jan. 02, 2026
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
  • 9.8

    CRITICAL
    CVE-2025-15434

    A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The manipulation of the argument zpjhid results in sql injection. It is possible to launch the attack remotely. The exploit is now public and m... Read more

    Affected Products : ksoa
    • Published: Jan. 02, 2026
    • Modified: Jan. 07, 2026
    • Vuln Type: Injection
Showing 20 of 4077 Results