Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2025-02-04 CVE-2025-1017 Out-of-bounds Write vulnerability in Mozilla Firefox
Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6.
network
low complexity
mozilla CWE-787
critical
9.8
2025-02-04 CVE-2025-1020 Out-of-bounds Write vulnerability in Mozilla Firefox
Memory safety bugs present in Firefox 134 and Thunderbird 134.
network
low complexity
mozilla CWE-787
critical
9.8
2025-02-04 CVE-2025-0890 **UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an attacker to log in to the management interface if the administrators have the option to change the default credentials but fail to do so.
network
low complexity
CWE-287
critical
9.8
2025-02-03 CVE-2025-24905 SQL Injection vulnerability in Wegia
WeGIA is a Web Manager for Charitable Institutions.
network
low complexity
wegia CWE-89
critical
9.8
2025-02-03 CVE-2025-24906 SQL Injection vulnerability in Wegia
WeGIA is a Web Manager for Charitable Institutions.
network
low complexity
wegia CWE-89
critical
9.8
2025-02-03 CVE-2025-24957 SQL Injection vulnerability in Wegia
WeGIA is a Web Manager for Charitable Institutions.
network
low complexity
wegia CWE-89
critical
9.8
2025-02-03 CVE-2024-45569 Improper Validation of Array Index vulnerability in Qualcomm products
Memory corruption while parsing the ML IE due to invalid frame content.
network
low complexity
qualcomm CWE-129
critical
9.8
2025-02-03 CVE-2024-49839 Out-of-bounds Read vulnerability in Qualcomm products
Memory corruption during management frame processing due to mismatch in T2LM info element.
network
low complexity
qualcomm CWE-125
critical
9.8
2025-02-03 CVE-2025-20634 Out-of-bounds Write vulnerability in Mediatek Nr16, Nr17 and Nr17R
In Modem, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
mediatek CWE-787
critical
9.8
2025-02-01 CVE-2025-0950 SQL Injection vulnerability in Angeljudesuarez Tailoring Management System 1.0
A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical.
network
low complexity
angeljudesuarez CWE-89
critical
9.8