7.3

CVSS3.1

CVE-2025-63932 -

D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote attacker can execute the shell command.

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 11, 2025, 6:23 p.m.

6.1

CVSS3.1

CVE-2025-63879 -

A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the id parameter.

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 12, 2025, 4:12 p.m.

7.5

CVSS3.1

CVE-2025-63208 -

An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint.

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 15, 2026, 9:52 p.m.

9.8

CVSS3.1

CVE-2025-63206 -

An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and 1.02.00, allowing attackers to gain escalated privileges via storing crafted cookies in the web browser.

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 31, 2025, 2:09 p.m.

5.4

CVSS3.1

CVE-2025-51662 -

A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inject arbitrary JavaScript code into shared text "codeboxes". The xss payload is automatically executed in the browsers oโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 24, 2025, 7:40 p.m.

6.1

CVSS3.1

CVE-2025-63211 -

Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5.0-10, allows attackers to execute arbitrary code via the addName parameter to the /vbc/core/userSetupDoc/userSetupDoc endpoint.

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 15, 2026, 6:51 p.m.

7.5

CVSS3.1

CVE-2025-51663 -

A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based rate limit protection and failed attempt restrictions by faking X-Real-IP and X-Forwarded-For HTTP headers. This can enable attackers to perform DoS attacks or brute force share cโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 24, 2025, 7:29 p.m.

7.5

CVSS3.1

CVE-2025-51661 -

A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct save_path and save fโ€ฆ

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 24, 2025, 7:35 p.m.

6.5

CVSS3.1

CVE-2025-63878 -

Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page.

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 31, 2025, 2:07 p.m.

7.5

CVSS3.1

CVE-2025-63371 -

Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents.

๐Ÿ“… Published: Nov. 19, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 11, 2025, 7:13 p.m.
Total resulsts: 349182
Page 2966 of 34,919
ยซ previous page ยป next page
Filters