Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2025-06-03 CVE-2025-25022 IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.
low complexity
CWE-260
critical
9.6
2025-06-03 CVE-2025-4797 The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.7.0.
network
low complexity
CWE-288
critical
9.8
2025-06-01 CVE-2025-5408 A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical.
network
low complexity
CWE-120
critical
9.8
2025-05-31 CVE-2025-4607 The PSW Front-end Login & Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12 via the customer_registration() function.
network
low complexity
CWE-330
critical
9.8
2025-05-31 CVE-2025-4631 The Profitori plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the stocktend_object endpoint in versions 2.0.6.0 to 2.1.1.3.
network
low complexity
CWE-285
critical
9.8
2025-05-31 CVE-2025-5367 SQL Injection vulnerability in PHPgurukul Online Shopping Portal 1.0
A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-05-31 CVE-2025-5365 SQL Injection vulnerability in Campcodes Online Hospital Management System 1.0
A vulnerability was found in Campcodes Online Hospital Management System 1.0.
network
low complexity
campcodes CWE-89
critical
9.8
2025-05-30 CVE-2025-5364 SQL Injection vulnerability in Campcodes Online Hospital Management System 1.0
A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as critical.
network
low complexity
campcodes CWE-89
critical
9.8
2025-05-30 CVE-2025-5362 Injection vulnerability in Campcodes Online Hospital Management System 1.0
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0.
network
low complexity
campcodes CWE-74
critical
9.8
2025-05-30 CVE-2025-5363 SQL Injection vulnerability in Campcodes Online Hospital Management System 1.0
A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical.
network
low complexity
campcodes CWE-89
critical
9.8