CVE Field Guide

Critical CVEs

CVE Title Updated Score
CVE-2025-40746 12.08.2025 9.4
CVE-2025-8059 B Blocks <= 2.0.6 - Missing Authorization to Unauthenticated Privilege Escalation via rgfr_registration Function 12.08.2025 9.8
CVE-2025-42950 Code Injection Vulnerability in SAP Landscape Transformation (Analysis Platform) 12.08.2025 9.9
CVE-2025-42957 Code Injection vulnerability in SAP S/4HANA (Private Cloud or On-Premise) 12.08.2025 9.9
CVE-2024-32640 MasaCMS SQL Injection vulnerability 11.08.2025 9.8
CVE-2012-10037 PhpTax pfilez Parameter Exec Remote Code Injection 11.08.2025 9.3
CVE-2012-10038 Auxilium RateMyPet Arbitrary File Upload RCE 11.08.2025 9.3
CVE-2012-10039 ZEN Load Balancer Filelog Command Execution 11.08.2025 9.4
CVE-2012-10040 Openfiler v2.x NetworkCard Command Execution 11.08.2025 9.4
CVE-2025-8853 2100 Technology|Official Document Management System - Authentication Bypass 11.08.2025 9.3
CVE-2025-54997 OpenBao: Privileged Operator May Execute Code on the Underlying Host 11.08.2025 9.1
CVE-2010-10013 AjaXplorer < 2.6 checkInstall.php Unauthenticated RCE 08.08.2025 9.3
CVE-2012-10036 Project Pier <= 0.8.8 Arbitrary File Upload RCE 08.08.2025 9.3
CVE-2012-10041 WAN Emulator v2.3 Command Execution 08.08.2025 9.3
CVE-2012-10043 ActFax 4.32 Client Importer Buffer Overflow 08.08.2025 9.3
CVE-2012-10044 MobileCartly 1.0 savepage.php Arbitrary File Creation 08.08.2025 10
CVE-2012-10045 XODA 0.4.5 Arbitrary PHP File Upload 08.08.2025 9.3
CVE-2012-10046 E-Mail Security Virtual Appliance learn-msg.cgi Command Injection 08.08.2025 9.3
CVE-2012-10047 Cyclope Employee Surveillance Solution v6.x SQL Injection 08.08.2025 10
CVE-2012-10049 WebPageTest Arbitrary PHP File Upload RCE 08.08.2025 9.3
CVE-2012-10050 CuteFlow <= 2.11.2 Arbitrary File Upload RCE 08.08.2025 9.3
CVE-2012-10052 EGallery 1.2 Arbitrary PHP File Upload 08.08.2025 9.3
CVE-2012-10053 Simple Web Server Connection Header Buffer Overflow 08.08.2025 9.3
CVE-2025-5095 Burk Technology ARC Solo Missing Authentication for Critical Function 08.08.2025 9.3
CVE-2025-46414 EG4 Electronics EG4 Inverters Improper Restriction of Excessive Authentication Attempts 08.08.2025 9.2
CVE-2025-8284 Packet Power EMX and EG Missing Authentication for Critical Function 08.08.2025 9.3
CVE-2025-8356 Path Traversal leading to RCE 08.08.2025 9.8
CVE-2025-8731 TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials 08.08.2025 9.3
CVE-2025-8730 Belkin F9K1009/F9K1010 Web Interface hard-coded credentials 08.08.2025 9.3
CVE-2025-54887 jwe: Missing AES-GCM authentication tag validation in encrypted JWEs 08.08.2025 9.1
CVE-2025-53767 Azure OpenAI Elevation of Privilege Vulnerability 08.08.2025 10
CVE-2025-53792 Azure Portal Elevation of Privilege Vulnerability 08.08.2025 9.1
CVE-2025-34148 Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via WISP SSID 07.08.2025 9.4
CVE-2025-34149 Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via WPA2 Key 07.08.2025 9.4
CVE-2025-34150 Shenzhen Aitemi M300 Wi-Fi Repeater PPPoE Username Command Injection 07.08.2025 9.4
CVE-2025-34151 Shenzhen Aitemi M300 Wi-Fi Repeater PPPoE Password Command Injection 07.08.2025 9.4
CVE-2025-34152 Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter 07.08.2025 9.4
CVE-2025-7768 Use of Hard-coded Credentials in Tigo Energy Cloud Connect Advanced 06.08.2025 9.3
CVE-2025-23311 06.08.2025 9.8
CVE-2025-23317 06.08.2025 9.1
CVE-2025-23310 06.08.2025 9.8
CVE-2025-22470 06.08.2025 9.3

Latest Updates

CVE Title Updated Score
CVE-2025-54864 Hydra missing authentication when triggering evaluations through GitHub and Gitea plugins 12.08.2025
CVE-2025-54800 Hydra persistent XSS in build metrics 12.08.2025
CVE-2025-8452 Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc. 12.08.2025 4.3
CVE-2025-5466 12.08.2025 4.9
CVE-2025-5468 12.08.2025 5.5
CVE-2025-5462 12.08.2025 7.5
CVE-2025-3831 Exposed SFTP server 12.08.2025 8.1
CVE-2025-5456 12.08.2025 7.5
CVE-2025-8296 12.08.2025 7.2
CVE-2025-8297 12.08.2025 7.2
CVE-2025-8310 12.08.2025 6.5
CVE-2024-38805 iSCSI Remote Memory Corruption and Denial of Service 12.08.2025 6.3
CVE-2025-22830 SmiFlash Race Condition Vulnerability 12.08.2025
CVE-2025-22834 ThirdPartyVideo SetVariable Vulnerability 12.08.2025 4.2
CVE-2025-43735 12.08.2025
CVE-2024-41979 12.08.2025 7.1
CVE-2024-41980 12.08.2025 3.1
CVE-2024-41982 12.08.2025 4.8
CVE-2024-41983 12.08.2025 3.5
CVE-2024-41984 12.08.2025 2.6
CVE-2024-41985 12.08.2025 2.6
CVE-2024-41986 12.08.2025 6.4
CVE-2024-52504 12.08.2025 7.5
CVE-2024-54678 12.08.2025 8.2
CVE-2025-30033 12.08.2025 7.8
CVE-2025-30034 12.08.2025 6.2
CVE-2025-33023 12.08.2025 4.1
CVE-2025-40570 12.08.2025 2.4
CVE-2025-40584 12.08.2025 5.5
CVE-2025-40743 12.08.2025 8.3
CVE-2025-40746 12.08.2025 9.1
CVE-2025-40751 12.08.2025 6.3
CVE-2025-40752 12.08.2025 6.2
CVE-2025-40753 12.08.2025 6.2
CVE-2025-40759 12.08.2025 7.8
CVE-2025-40761 12.08.2025 7.6
CVE-2025-40762 12.08.2025 7.8
CVE-2025-40764 12.08.2025 7.8
CVE-2025-40766 12.08.2025 5.5
CVE-2025-40767 12.08.2025 7.8
CVE-2025-40768 12.08.2025 7.3
CVE-2025-40769 12.08.2025 7.4
CVE-2025-40770 12.08.2025 7.4
CVE-2025-43736 12.08.2025
CVE-2025-8885 Possible DOS in processing specially formed ASN.1 Object Identifiers 12.08.2025
CVE-2025-26398 SolarWinds Database Performance Analyzer Hard-coded Cryptographic Key Vulnerability 12.08.2025 5.6
CVE-2025-41686 Improper File Permissions Allow Local Privilege Escalation 12.08.2025 7.8
CVE-2025-47444 WordPress GiveWP Plugin < 4.6.1 is vulnerable to Sensitive Data (PII) Exposure 12.08.2025 7.5
CVE-2025-8418 B Slider- Gutenberg Slider Block for WP <= 1.1.30 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Plugin Installation 12.08.2025 8.8
CVE-2025-8482 Simple Local Avatars <= 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Avatar Migration 12.08.2025 4.3
CVE-2025-8767 AnWP Football Leagues <= 0.16.17 - Authenticated (Administrator+) CSV Injection 12.08.2025 4.8
CVE-2025-8874 Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fancyBox 12.08.2025 6.4
CVE-2025-6253 UiCore Elements <= 1.3.0 - Missing Authorization to Unauthenticated Arbitrary File Read 12.08.2025 7.5
CVE-2025-8081 Elementor <= 3.30.2 - Authenticated (Administrator+) Arbitrary File Read via Image Import 12.08.2025 4.9
CVE-2025-30027 12.08.2025 6.7
CVE-2025-3892 12.08.2025 6.7
CVE-2025-7622 12.08.2025