8.7

CVSS4.0

CVE-2025-13400 - Tenda CH22 WrlExtraGet formWrlExtraGet buffer overflow

A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtraGet. Performing a manipulation of the argument chkHz results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.

📅 Published: Nov. 19, 2025, 5:02 p.m. 🔄 Last Modified: Feb. 24, 2026, 7:16 a.m.

6

CVSS4.0

CVE-2025-12743 - SQL Injection in Looker Project Generation Endpoint Allows Access to Internal MySQL Database

The Looker endpoint for generating new projects from database connections allows users to specify "looker" as a connection name, which is a reserved internal name for Looker's internal MySQL database. The schemas parameter is vulnerable to SQL injection, enabling attackers to manipulate SELECT quer…

📅 Published: Nov. 19, 2025, 4:41 p.m. 🔄 Last Modified: Nov. 24, 2025, 9:10 a.m.

6.9

CVSS4.0

CVE-2025-64765 - Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values

Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for routing/rendering and how the application’s middleware reads the path for validation checks. Astro internally applies decodeURI() to determine which route to render, while the middlew…

📅 Published: Nov. 19, 2025, 4:41 p.m. 🔄 Last Modified: Nov. 25, 2025, 3:11 p.m.

7.1

CVSS3.1

CVE-2025-64764 - Astro is vulnerable to Reflected XSS via the server islands feature

Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.

📅 Published: Nov. 19, 2025, 4:41 p.m. 🔄 Last Modified: Nov. 20, 2025, 5:54 p.m.

5.4

CVSS3.1

CVE-2025-65019 - Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint

Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that unconditionally allows data: protocol URLs. This e…

📅 Published: Nov. 19, 2025, 4:40 p.m. 🔄 Last Modified: Nov. 25, 2025, 3:09 p.m.

3.5

CVSS3.1

CVE-2025-64757 - Astro Development Server is Vulnerable to Arbitrary Local File Read

Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and allows remote attacke…

📅 Published: Nov. 19, 2025, 4:40 p.m. 🔄 Last Modified: Nov. 20, 2025, 5:58 p.m.

8.7

CVSS4.0

CVE-2025-34335 - AudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via ActivateLicense.php

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the license activation workflow handled by AudioCodes_files/ActivateLicense.php. When a license file is uploaded, the application derives a new file…

📅 Published: Nov. 19, 2025, 4:24 p.m. 🔄 Last Modified: Dec. 11, 2025, 9:11 p.m.

8.7

CVSS4.0

CVE-2025-34334 - AudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via TestFax.php & LPE

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax test functionality implemented by AudioCodes_files/TestFax.php. When a fax "send" test is requested, the application builds a faxsender command…

📅 Published: Nov. 19, 2025, 4:23 p.m. 🔄 Last Modified: Dec. 11, 2025, 9:12 p.m.

8.5

CVSS4.0

CVE-2025-34332 - AudioCodes Fax/IVR Appliance <= 2.6.23 Insecure Service Control Scripts LPE

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain service actions are …

📅 Published: Nov. 19, 2025, 4:23 p.m. 🔄 Last Modified: Dec. 11, 2025, 9:19 p.m.

9.3

CVSS4.0

CVE-2025-34329 - AudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated Backup Upload RCE via ajaxBackupUploadFile.p…

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFile.php in the F2MAdmin web interface. The script derives a backup folder path from application configuration, creates th…

📅 Published: Nov. 19, 2025, 4:23 p.m. 🔄 Last Modified: Dec. 12, 2025, 4:09 p.m.
Total resulsts: 342367
Page 2280 of 34,237
« previous page » next page
Filters