{"@context":{"@vocab":"https://schema.org/"},"@type":"ItemList","@id":"https://api.ai-analytics.org/api/v1/cves/critical","_source":{"data_provider":"AI Analytics","data_provider_url":"https://api.ai-analytics.org","license":"https://creativecommons.org/publicdomain/zero/1.0/","primary_source":"https://nvd.nist.gov","generated_at":"2026-08-01T06:56:27.489Z"},"count":25,"items":[{"cve_id":"CVE-2025-27007","source":"audit@patchstack.com","published":"2025-05-01","last_modified":"2026-04-23","vuln_status":"Deferred","description":"Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-266","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-47154","source":"cve@mitre.org","published":"2025-05-01","last_modified":"2026-04-15","vuln_status":"Deferred","description":"LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says \"Ladybird is in a pre-alpha state, and only suitable for use by developers.\"","cvss_v3_score":9,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-820","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-4144","source":"cna@cloudflare.com","published":"2025-05-01","last_modified":"2025-05-12","vuln_status":"Analyzed","description":"PKCE was implemented in the OAuth implementation in workers-oauth-provider that is part of  MCP framework https://github.com/cloudflare/workers-mcp . However, it was found that an attacker could cause the check to be skipped.\n\n\nFixed in:\n\n \n\n https://github.com/cloudflare/workers-oauth-provider/pull/27 https://github.com/cloudflare/workers-oauth-provider/pull/27 \n\n\nImpact: \n\nPKCE is a defense-in-depth mechanism against certain kinds of attacks and was an optional extension in OAuth 2.0 which became required in the OAuth 2.1 draft. (Note that the MCP specification requires OAuth 2.1.). This bug completely bypasses PKCE protection.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-287","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-46558","source":"security-advisories@github.com","published":"2025-04-30","last_modified":"2025-08-26","vuln_status":"Analyzed","description":"XWiki Contrib's Syntax Markdown allows importing Markdown content into wiki pages and creating wiki content in Markdown. In versions starting from 8.2 to before 8.9, the Markdown syntax is vulnerable to cross-site scripting (XSS) through HTML. In particular, using Markdown syntax, it's possible for any user to embed Javascript code that will then be executed on the browser of any other user visiting either the document or the comment that contains it. In the instance that this code is executed by a user with admins or programming rights, this issue compromises the confidentiality, integrity and availability of the whole XWiki installation. This issue has been patched in version 8.9.","cvss_v3_score":9,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-79","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-46557","source":"security-advisories@github.com","published":"2025-04-30","last_modified":"2025-09-03","vuln_status":"Analyzed","description":"XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, a user who can access pages located in the XWiki space (by default, anyone) can access the page XWiki.Authentication.Administration and (unless an authenticator is set in xwiki.cfg) switch to another installed authenticator. Note that, by default, there is only one authenticator available (Standard XWiki Authenticator). So, if no authenticator extension was installed, it's not really possible to do anything for an attacker. Also, in most cases, if an SSO authenticator is installed and utilized (like OIDC or LDAP for example), the worst an attacker can do is break authentication by switching back to the standard authenticator (that's because it's impossible to login to a user which does not have a stored password, and that's usually what SSO authenticator produce). This issue has been patched in versions 15.10.14, 16.4.6, and 16.10.0-rc-1.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-862","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-46331","source":"security-advisories@github.com","published":"2025-04-30","last_modified":"2025-12-31","vuln_status":"Analyzed","description":"OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. This issue has been patched in version 1.8.11.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-284","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-44192","source":"cve@mitre.org","published":"2025-04-30","last_modified":"2025-05-12","vuln_status":"Analyzed","description":"SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-89","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-30392","source":"secure@microsoft.com","published":"2025-04-30","last_modified":"2025-05-12","vuln_status":"Analyzed","description":"Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-285","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-30390","source":"secure@microsoft.com","published":"2025-04-30","last_modified":"2025-05-12","vuln_status":"Analyzed","description":"Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.","cvss_v3_score":9.9,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-285","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-32974","source":"security-advisories@github.com","published":"2025-04-30","last_modified":"2025-05-13","vuln_status":"Analyzed","description":"XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAreas with default content type. When editing a page, XWiki warns since version 15.9 when there is content on the page like a script macro that would gain more rights due to the editing. This analysis doesn't consider certain kinds of properties, allowing a user to put malicious scripts in there that will be executed after a user with script, admin, or programming rights edited the page. Such a malicious script could impact the confidentiality, integrity and availability of the whole XWiki installation. This issue has been patched in versions 15.10.8 and 16.2.0.","cvss_v3_score":9,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-116,CWE-269","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-32973","source":"security-advisories@github.com","published":"2025-04-30","last_modified":"2025-05-13","vuln_status":"Analyzed","description":"XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, when a user with programming rights edits a document in XWiki that was last edited by a user without programming rights and contains an XWiki.ComponentClass, there is no warning that this will grant programming rights to this object. An attacker who created such a malicious object could use this to gain programming rights on the wiki. For this, the attacker needs to have edit rights on at least one page to place this object and then get an admin user to edit that document. This issue has been patched in versions 15.10.12, 16.4.3, and 16.8.0-rc-1.","cvss_v3_score":9,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-862","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-45018","source":"cve@mitre.org","published":"2025-04-30","last_modified":"2025-05-09","vuln_status":"Analyzed","description":"A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-89","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-45017","source":"cve@mitre.org","published":"2025-04-30","last_modified":"2025-05-09","vuln_status":"Analyzed","description":"A SQL injection vulnerability was discovered in edit-ticket.php of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the tprice POST request parameter.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-89","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-32444","source":"security-advisories@github.com","published":"2025-04-30","last_modified":"2025-05-28","vuln_status":"Analyzed","description":"vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based serialization over unsecured ZeroMQ sockets. The vulnerable sockets were set to listen on all network interfaces, increasing the likelihood that an attacker is able to reach the vulnerable ZeroMQ sockets to carry out an attack. vLLM instances that do not make use of the mooncake integration are not vulnerable. This issue has been patched in version 0.8.5.","cvss_v3_score":10,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-502","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-46348","source":"security-advisories@github.com","published":"2025-04-29","last_modified":"2025-05-09","vuln_status":"Analyzed","description":"YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could create and download an archive without being authenticated. This could result in a malicious attacker making numerous requests to create archives and fill up the file system, or by downloading the archive which contains sensitive site information. This issue has been patched in version 4.5.4.","cvss_v3_score":10,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-287,CWE-862","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-46347","source":"security-advisories@github.com","published":"2025-04-29","last_modified":"2025-05-09","vuln_status":"Analyzed","description":"YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki vulnerable to remote code execution. An arbitrary file write can be used to write a file with a PHP extension, which then can be browsed to in order to execute arbitrary code on the server, resulting in a full compromise of the server. This could potentially be performed unwittingly by a user. This issue has been patched in version 4.5.4.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-116","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-40618","source":"cve-coordination@incibe.es","published":"2025-04-29","last_modified":"2025-10-14","vuln_status":"Analyzed","description":"SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the \"IDRESERVA\"  parameter in /bkg_imprimir_comprobante.php","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-89","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-40617","source":"cve-coordination@incibe.es","published":"2025-04-29","last_modified":"2025-10-14","vuln_status":"Analyzed","description":"SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the \"IDTIPO\", \"IDPISTA\" and \"IDSOCIO\" parameters in /bkg_seleccionar_hora_ajax.php.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-89","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-25962","source":"cve@mitre.org","published":"2025-04-29","last_modified":"2026-04-15","vuln_status":"Deferred","description":"An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the _modifyPosition function","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-269,CWE-284","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-25403","source":"cve@mitre.org","published":"2025-04-29","last_modified":"2026-04-15","vuln_status":"Deferred","description":"Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-89","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-4083","source":"security@mozilla.org","published":"2025-04-29","last_modified":"2026-04-13","vuln_status":"Modified","description":"A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10.","cvss_v3_score":9.1,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-653","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-45953","source":"cve@mitre.org","published":"2025-04-28","last_modified":"2025-04-30","vuln_status":"Analyzed","description":"A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely","cvss_v3_score":9.1,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-384","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-45949","source":"cve@mitre.org","published":"2025-04-28","last_modified":"2025-04-30","vuln_status":"Analyzed","description":"A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely and leading to account takeover.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-384","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-45947","source":"cve@mitre.org","published":"2025-04-28","last_modified":"2025-04-30","vuln_status":"Analyzed","description":"An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-94","ingested_at":"2026-05-20 02:37:14"},{"cve_id":"CVE-2025-31651","source":"security@apache.org","published":"2025-04-28","last_modified":"2025-11-03","vuln_status":"Modified","description":"Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible \nfor a specially crafted request to bypass some rewrite rules. If those \nrewrite rules effectively enforced security constraints, those \nconstraints could be bypassed.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.5, from 10.1.0-M1 through 10.1.39, from 9.0.0.M1 through 9.0.102.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions \nmay also be affected.\n\n\nUsers are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.","cvss_v3_score":9.8,"cvss_v3_severity":"CRITICAL","cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v2_score":null,"cvss_v2_severity":null,"cwe_ids":"CWE-116","ingested_at":"2026-05-20 02:37:14"}]}