6.3

CVSS4.0

CVE-2025-9262 - wong2 mcp-cli oAuth provider.js redirectToAuthorization os command injection

A flaw has been found in wong2 mcp-cli 1.13.0. Affected is the function redirectToAuthorization of the file /src/oauth/provider.js of the component oAuth Handler. This manipulation causes os command injection. The attack may be initiated remotely. The attack is considered to have high complexity. T…

πŸ“… Published: Aug. 20, 2025, 11:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 11:02 p.m.

8.7

CVSS4.0

CVE-2025-9253 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_doSpecifySiteSurvey stack-based overflow

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this issue is the function RP_doSpecifySiteSurvey of the file /goform/RP_doSpecifySiteSurvey. The manipulation of the argument…

πŸ“… Published: Aug. 20, 2025, 10:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 10:32 p.m.

8.7

CVSS4.0

CVE-2025-9252 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 DisablePasswordAlertRedirect stack-based overflow

A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected by this vulnerability is the function DisablePasswordAlertRedirect of the file /goform/DisablePasswordAlertRedirect. Executing manipulation o…

πŸ“… Published: Aug. 20, 2025, 10:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 10:02 p.m.

8.7

CVSS4.0

CVE-2025-9251 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 sta_wps_pin stack-based overflow

A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Affected is the function sta_wps_pin of the file /goform/sta_wps_pin. Performing manipulation of the argument Ssid results in stack-based buffer …

πŸ“… Published: Aug. 20, 2025, 10:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 10:02 p.m.

9.1

CVSS4.0

CVE-2025-9288 - Missing type checks leading to hash rewind and passing on crafted data

Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.

πŸ“… Published: Aug. 20, 2025, 9:59 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 9:59 p.m.

6.5

CVSS3.1

CVE-2025-57749 - n8n has a symlink traversal vulnerability in "Read/Write File" node allows access to restricted fil…

n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict access to sensitive directories and files, it does not properly account for symbolic links (symlinks). An attacker with the…

πŸ“… Published: Aug. 20, 2025, 9:46 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 9:46 p.m.

9.1

CVSS4.0

CVE-2025-9287 - Missing type checks leading to hash rewind and passing on crafted data

Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.

πŸ“… Published: Aug. 20, 2025, 9:43 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 9:43 p.m.

8.7

CVSS4.0

CVE-2025-9250 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setPWDbyBBS stack-based overflow

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This impacts the function setPWDbyBBS of the file /goform/setPWDbyBBS. Such manipulation of the argument hint leads to stack-based buffer overflow. It…

πŸ“… Published: Aug. 20, 2025, 9:32 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 9:32 p.m.

8.7

CVSS4.0

CVE-2025-9249 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 DHCPReserveAddGroup stack-based overflow

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function DHCPReserveAddGroup of the file /goform/DHCPReserveAddGroup. This manipulation of the argument enable_group/name_group/ip_gr…

πŸ“… Published: Aug. 20, 2025, 9:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 9:02 p.m.

8.7

CVSS4.0

CVE-2025-9248 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_pingGatewayByBBS stack-based overflow

A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The impacted element is the function RP_pingGatewayByBBS of the file /goform/RP_pingGatewayByBBS. The manipulation of the argument ssidhex results in stack…

πŸ“… Published: Aug. 20, 2025, 9:02 p.m. πŸ”„ Last Modified: Aug. 20, 2025, 9:02 p.m.
Total resulsts: 306413
Page 2 of 30,642
Β« previous page Β» next page
Filters