6.5

CVSS3.1

CVE-2025-43989 -

The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandles the set_timesetting action with the ntpserver0 parameter, which is used in a system command. By setting a username=admin cookie (bypassing normal session checks), an unauthenti…

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 9:15 p.m.

0.0

CVE-2025-50613 -

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00475e1c function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wds_key_wep in the payload, which can cause the program to crash and potentially lead to a Denial…

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 5:33 p.m.

0.0

CVE-2025-50608 -

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00471994 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wl_base_set in the payload, which can cause the program to crash and potentially lead to a Denial…

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 1:38 p.m.

0.0

CVE-2025-43982 -

Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that cannot be disabled in the GUI.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 1:11 p.m.

6.1

CVSS3.1

CVE-2025-50690 -

A Cross-Site Scripting (XSS) vulnerability exists in SpatialReference.org (OSGeo/spatialreference.org) versions prior to 2025-05-17 (commit 2120adfa17ddd535bd0f539e6c4988fa3a2cb491). The vulnerability is caused by improper handling of user input in the search query parameter. An attacker can craft …

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 9:15 p.m.

0.0

CVE-2025-52385 -

An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process module

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 5:33 p.m.

0.0

CVE-2025-43986 -

An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WAN interface without authentication.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 1:11 p.m.

6.1

CVSS3.1

CVE-2025-45313 -

A cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the title parameter.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 9:15 p.m.

0.0

CVE-2025-43988 -

KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers to retrieve sensitive configuration data, including admin credentials.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 1:11 p.m.

7.5

CVSS3.1

CVE-2025-50616 -

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046f984 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wl_advanced_set in the payload, which can cause the program to crash and lead to a Denial of Serv…

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 9:15 p.m.
Total resulsts: 306274
Page 106 of 30,628
Β« previous page Β» next page
Filters