9.8

CVSS3.1

CVE-2025-60738 -

An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute arbitrary code via the ping.php component does not perform secure filtering on IP parameters

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 6:57 p.m.

4.3

CVSS3.1

CVE-2025-65222 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 5:25 p.m.

4.3

CVSS3.1

CVE-2025-65220 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 5:26 p.m.

4.3

CVSS3.1

CVE-2025-65226 -

Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 21, 2025, 5:24 p.m.

7.5

CVSS3.1

CVE-2025-63889 -

The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary files via crafted file path in a template value.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 3:41 p.m.

6.1

CVSS3.1

CVE-2025-60737 -

Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /index.php component

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 3:32 p.m.

7.5

CVSS3.1

CVE-2025-25613 -

FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing usernames and passwords. These were transmitted in cleartext using…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Jan. 15, 2026, 8:08 p.m.

9.8

CVSS3.1

CVE-2025-63888 -

The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 3:40 p.m.

6.5

CVSS3.1

CVE-2025-60797 -

phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application directly executes user-supplied SQL queries from the $_REQUEST['query'] parameter without any sanitization or parameterization via $data->conn->Execute($_REQUEST['query']). An authent…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 7:13 p.m.

9.8

CVSS3.1

CVE-2025-63685 -

Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of system libraries. Specifically, the application does not validate the path or signature of [regsvr32.exe] it loads. An attacker can place a crafted malicious DLL in the application's s…

πŸ“… Published: Nov. 20, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 6:05 p.m.
Total resulsts: 346699
Page 2707 of 34,670
Β« previous page Β» next page
Filters