8.6
CVE-2025-15065 - Data Exposure in Kings Information & Network KESS Enterprise
Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Information & Network Co. KESS Enterprise on Windows allows Privilege Escalation, Modify Existing Service, Modify Shared File.β¦
8.6
CVE-2025-15163 - Tenda WH450 SafeEmailFilter stack-based overflow
A vulnerability was identified in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/SafeEmailFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly avβ¦
9.8
CVE-2025-56333 -
An issue in Fossorial fosrl/pangolin v.1.6.2 and before allows a remote attacker to escalate privileges via the 2FA component
9.8
CVE-2025-68706 -
A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attackβ¦
2.5
CVE-2025-66861 - binutils: out-of-bounds read in d_unqualified_name() in cp-demangle.c
An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.
7.5
CVE-2025-67254 -
NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.
8.8
CVE-2024-30855 -
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.
5.5
CVE-2025-66864 - binutils: NULL pointer dereference in d_print_comp_inner() in cp-demangle.c
An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
9.8
CVE-2025-57460 -
File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
7.5
CVE-2024-25183 -
givanz VvvebJs 1.7.2 is vulnerable to Directory Traversal via scan.php.