CVE ID | Publié | Description | Score | Gravité | |
---|---|---|---|---|---|
CVE-2025-2605 |
2025-05-02 12h39 +00:00 |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi... OS Command Injection |
9.9 |
Critique |
|
CVE-2025-2421 |
2025-05-02 11h27 +00:00 |
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics Samb... Code Injection |
8.2 |
Haute |
|
CVE-2025-2812 |
2025-05-02 08h24 +00:00 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i... SQL Injection |
9.8 |
Critique |
|
CVE-2024-13418 |
2025-05-02 03h21 +00:00 |
Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missi... File Inclusion |
8.8 |
Haute |
|
CVE-2025-3708 |
2025-05-02 02h55 +00:00 |
Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing u... SQL Injection |
9.8 |
Critique |
|
CVE-2025-3709 |
2025-05-02 03h13 +00:00 |
Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthentic... |
9.8 |
Critique |
|
CVE-2025-3746 |
2025-05-02 01h43 +00:00 |
The OTP-less one tap Sign in plugin for WordPress is vulnerable to privilege escalation via account ... Authorization problems |
9.8 |
Critique |
|
CVE-2025-43595 |
2025-05-01 21h12 +00:00 |
An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged... |
8.5 |
Haute |
|
CVE-2025-46625 |
2025-05-01 00h00 +00:00 |
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro ... Command Injection |
8.8 |
Haute |
|
CVE-2025-46627 |
2025-05-01 00h00 +00:00 |
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authe... |
8.2 |
Haute |