Real-time Vulnerability Intelligence

Security Intelligence Hub

Stay ahead of threats with real-time CVE data from NVD and CISA KEV. AI-powered explanations help you understand and remediate vulnerabilities faster.

Recent Critical Vulnerabilities

Latest high-impact security issues requiring attention

View all
10.0 CRITICAL

CVE-2025-52691

2025-12-29

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

EPSS
0.2%
7.3 HIGH

CVE-2025-15168

2025-12-29

A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /statistical.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

EPSS
0.0%
7.3 HIGH

CVE-2025-15167

2025-12-29

A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the file /detailtransac.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

EPSS
0.0%
7.3 HIGH

CVE-2025-15166

2025-12-29

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file /updatesupplier.php?action=edit. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

EPSS
0.0%
7.3 HIGH

CVE-2025-15165

2025-12-29

A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown function of the file /updatecustomer.php?action=edit. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

EPSS
0.0%
7.2 HIGH

CVE-2025-15164

2025-12-29

A security flaw has been discovered in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/SafeMacFilter. The manipulation of the argument page results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be exploited.

EPSS
0.0%
7.2 HIGH

CVE-2025-15163

2025-12-29

A vulnerability was identified in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

EPSS
0.0%
7.7 HIGH

CVE-2025-15067

2025-12-29

Unrestricted Upload of File with Dangerous Type vulnerability in Innorix Innorix WP allows Upload a Web Shell to a Web Server.This issue affects Innorix WP from All versions If the "exam" directory exists under the directory where the product is installed (ex: innorix/exam)

EPSS
0.0%
7.2 HIGH

CVE-2025-15162

2025-12-29

A vulnerability was determined in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/RouteStatic. Executing manipulation of the argument page can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

EPSS
0.0%
7.2 HIGH

CVE-2025-15161

2025-12-28

A vulnerability was found in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/PPTPUserSetting. Performing manipulation of the argument delno results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

EPSS
0.0%