5.1

CVSS4.0

CVE-2025-3816 - westboy CicadasCMS Scheduled Task save os command injection

A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Task Handler. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been dโ€ฆ

๐Ÿ“… Published: April 19, 2025, 6 p.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.3

CVSS4.0

CVE-2025-3808 - zhenfeng13 My-BBS cross-site request forgery

A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Multiple endpointโ€ฆ

๐Ÿ“… Published: April 19, 2025, 5:31 p.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.3

CVSS4.0

CVE-2025-3807 - zhenfeng13 My-BBS Endpoint UploadController.java upload unrestricted upload

A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/UploadController.java of the component Endpoint. The manipulation leads to unrestricted upload. It is possible to initiate tโ€ฆ

๐Ÿ“… Published: April 19, 2025, 5 p.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.8

CVSS4.0

CVE-2025-3806 - dazhouda lecms Edit Profile admin cross site scripting

A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3. Affected by this issue is some unknown functionality of the file /admin of the component Edit Profile Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. Theโ€ฆ

๐Ÿ“… Published: April 19, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.8

CVSS4.0

CVE-2025-3805 - sarrionandia tournatrack Jinja2 Template check_id.py injection

A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. Affected by this vulnerability is an unknown functionality of the file check_id.py of the component Jinja2 Template Handler. The manipulation of the argument ID leads to injeโ€ฆ

๐Ÿ“… Published: April 19, 2025, 4 p.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

4.8

CVSS4.0

CVE-2025-3804 - thautwarm vscode-diana Jinja2 Template Gen.py injection

A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public aโ€ฆ

๐Ÿ“… Published: April 19, 2025, 3:31 p.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

8.7

CVSS4.0

CVE-2025-3803 - Tenda W12/i24 httpd cgiSysScheduleRebootSet stack-based overflow

A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysScheduleRebootSet of the file /bin/httpd. The manipulation of the argument rebootDate leads to stack-based buffer overflow. The attack may be initiated reโ€ฆ

๐Ÿ“… Published: April 19, 2025, 3 p.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

8.7

CVSS4.0

CVE-2025-3802 - Tenda W12/i24 httpd cgiPingSet stack-based overflow

A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function cgiPingSet of the file /bin/httpd. The manipulation of the argument pingIP leads to stack-based buffer overflow. The attack can be initiated remotelyโ€ฆ

๐Ÿ“… Published: April 19, 2025, 2:31 p.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:58 p.m.

4.8

CVSS4.0

CVE-2025-3801 - songquanpeng one-api System Setting cross site scripting

A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content/About System/Footer leads to cross site scripting. It is possible to initiatโ€ฆ

๐Ÿ“… Published: April 19, 2025, 2 p.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.

6.9

CVSS4.0

CVE-2025-3800 - WCMS AnonymousController.php sql injection

A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php. The manipulation of the argument mobile_phone leads to sql injection. The attack can be launched remotely. The exploiโ€ฆ

๐Ÿ“… Published: April 19, 2025, 11:31 a.m. ๐Ÿ”„ Last Modified: April 21, 2025, 2:23 p.m.
Total resulsts: 291112
Page 17 of 29,112
ยซ previous page ยป next page
Filters