Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2025-03-03 CVE-2025-1875 SQL Injection vulnerability in Mayurik Best Online News Portal 1.0
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php.
network
low complexity
mayurik CWE-89
critical
9.8
2025-03-03 CVE-2025-1859 Injection vulnerability in PHPgurukul News Portal 4.1
A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1.
network
low complexity
phpgurukul CWE-74
critical
9.8
2025-03-03 CVE-2025-1852 Classic Buffer Overflow vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316
A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical.
network
low complexity
totolink CWE-120
critical
9.8
2025-03-03 CVE-2025-1853 Stack-based Buffer Overflow vulnerability in Tenda AC8 Firmware 16.03.34.06
A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical.
network
low complexity
tenda CWE-121
critical
9.8
2025-03-03 CVE-2025-1850 Unspecified vulnerability in Codezips College Management System 1.0
A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0.
network
low complexity
codezips
critical
9.8
2025-03-03 CVE-2025-27590 Unspecified vulnerability in Oxidized web Project Oxidized web
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.
network
low complexity
oxidized-web-project
critical
9.8
2025-03-02 CVE-2025-1814 Stack-based Buffer Overflow vulnerability in Tenda AC6 Firmware 15.03.05.16
A vulnerability, which was classified as critical, has been found in Tenda AC6 15.03.05.16.
network
low complexity
tenda CWE-121
critical
9.8
2025-03-01 CVE-2025-1564 The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3.
network
low complexity
CWE-288
critical
9.8
2025-03-01 CVE-2025-1638 The Alloggio Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2.
network
low complexity
CWE-288
critical
9.8
2025-03-01 CVE-2025-1671 The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6.
network
low complexity
CWE-288
critical
9.8