Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2025-05-26 CVE-2025-5172 Injection vulnerability in Econtrata
A vulnerability, which was classified as critical, was found in Econtrata up to 20250516.
network
low complexity
econtrata CWE-74
critical
9.8
2025-05-26 CVE-2025-5170 Injection vulnerability in Llisoft MTA Maita Training System 4.5
A vulnerability classified as critical was found in llisoft MTA Maita Training System 4.5.
network
low complexity
llisoft CWE-74
critical
9.8
2025-05-26 CVE-2025-5162 Unrestricted Upload of File with Dangerous Type vulnerability in H3C Seccenter Smp-1114P02
A vulnerability, which was classified as critical, has been found in H3C SecCenter SMP-E1114P02 up to 20250513.
network
low complexity
h3c CWE-434
critical
9.8
2025-05-26 CVE-2025-2146 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.
network
low complexity
canon CWE-787
critical
9.8
2025-05-25 CVE-2025-5156 A vulnerability was found in H3C GR-5400AX up to 100R008 and classified as critical.
network
low complexity
CWE-120
critical
9.8
2025-05-24 CVE-2025-4603 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up to, and including, 1.2.5.
network
low complexity
CWE-73
critical
9.1
2025-05-24 CVE-2025-5058 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all versions up to, and including, 1.2.5.
network
low complexity
CWE-434
critical
9.8
2025-05-23 CVE-2024-51101 SQL Injection vulnerability in PHPgurukul Restaurant Table Booking System 1.0
PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /rtbs/check-status.php.
network
low complexity
phpgurukul CWE-89
critical
9.8
2025-05-23 CVE-2024-51360 Unspecified vulnerability in PHPgurukul Hospital Management System 4.0
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file
network
low complexity
phpgurukul
critical
9.8
2025-05-22 CVE-2025-5081 Injection vulnerability in Campcodes Cybercafe Management System 1.0
A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0.
network
low complexity
campcodes CWE-74
critical
9.8