5.1

CVSS4.0

CVE-2025-64716 - Anubis vulnerable to possible XSS via redir parameter when using subrequest auth mode

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. Prior to version 1.23.0, when using subrequest authentication, Anubis did not perform validation of the redirect URL and redirects user to any URL scheme. While most mode…

πŸ“… Published: Nov. 13, 2025, 1:46 a.m. πŸ”„ Last Modified: Nov. 14, 2025, 4:42 p.m.

5.3

CVSS4.0

CVE-2025-64710 - Bitplatform Boilerplate has cross-site scripting vulnerability

Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-site scripting (XSS) vulnerability in the WebInteropApp/WebAppInterop, potentially allowing attackers to inject malicious scripts that compromise the security and integrity of web …

πŸ“… Published: Nov. 13, 2025, 1:40 a.m. πŸ”„ Last Modified: Nov. 13, 2025, 1:40 a.m.

6.5

CVSS3.1

CVE-2025-60676 -

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' and 'SubnetMask' parameters are directly concatenated into shell commands executed vi…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:16 p.m.

5.4

CVSS3.1

CVE-2025-60671 -

A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /var/system/linux_vlan_reinit file. The vulnerability occurs because content read from this file is only partially validated for …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 6:15 p.m.

8.8

CVSS3.1

CVE-2025-60679 -

A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and then concatenated usin…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 6:15 p.m.

6.5

CVSS3.1

CVE-2025-60701 -

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_433188` function in `prog.cgi` stores user-supplied email configuration parameters (`EmailFrom`, `EmailTo`, `SMTPServerAddress`, `SMTPServerPort`, `Acco…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:16 p.m.

5.3

CVSS3.1

CVE-2025-47221 -

Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 2 of 3.

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 6:15 p.m.

8.8

CVSS3.1

CVE-2025-63406 -

An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToApi() and eval() in the FunctionField.php

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:16 p.m.

6.5

CVSS3.1

CVE-2025-60702 -

A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user input via `websGetVar` and concatenates it directly into a `ping` system command execut…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:16 p.m.

5.4

CVSS3.1

CVE-2025-60675 -

A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the timelycheck and sysconf binaries, which process the /tmp/new_qos.rule configuration file. The vulnerability occurs because parsed fields from the configuration file are concatenated…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 7:16 p.m.
Total resulsts: 318415
Page 28 of 31,842
Β« previous page Β» next page
Filters