9.1

CVSS3.1

CVE-2025-50251 -

Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 9:47 p.m.

6.5

CVSS3.1

CVE-2025-50946 -

OS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 9:15 p.m.

5.4

CVSS3.1

CVE-2025-45315 -

A cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the email parameter.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 9:15 p.m.

6.1

CVSS3.1

CVE-2025-51691 -

Cross-Site Scripting (XSS) vulnerability found in MarkTwo commit e3a1d3f90cce4ea9c26efcbbf3a1cbfb9dcdb298 (May 2025) allows a remote attacker to execute arbitrary code via a crafted script input to the editor interface. The application does not properly sanitize user-supplied Markdown before render…

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 8:15 p.m.

0.0

CVE-2025-43988 -

KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers to retrieve sensitive configuration data, including admin credentials.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 1:11 p.m.

6.5

CVSS3.1

CVE-2025-43989 -

The /goform/formJsonAjaxReq POST endpoint of Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices mishandles the set_timesetting action with the ntpserver0 parameter, which is used in a system command. By setting a username=admin cookie (bypassing normal session checks), an unauthenti…

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 9:15 p.m.

7.8

CVSS3.1

CVE-2025-8941 - Linux-pam: incomplete fix for cve-2025-6020

A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks and race conditions to elevate their privileges to root. This CVE provides a "complete" fix for CVE-2025-6020.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 3:56 a.m.

0.0

CVE-2025-50608 -

A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00471994 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wl_base_set in the payload, which can cause the program to crash and potentially lead to a Denial…

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 1:38 p.m.

0.0

CVE-2025-43982 -

Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden hard-coded root account that cannot be disabled in the GUI.

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 1:11 p.m.

0.0

CVE-2025-52385 -

An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process module

πŸ“… Published: Aug. 13, 2025, midnight πŸ”„ Last Modified: Aug. 13, 2025, 5:33 p.m.
Total resulsts: 306288
Page 107 of 30,629
Β« previous page Β» next page
Filters