8.7

CVSS4.0

CVE-2025-12259 - TOTOLINK A3300R POST Parameter cstecgi.cgi setScheduleCfg stack-based overflow

A flaw has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024. The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component POST Parameter Handler. This manipulation of the argument recHour causes stack-based buffer overflow. It is possible to initiate the…

📅 Published: Oct. 27, 2025, 10:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:09 a.m.

9.3

CVSS3.1

CVE-2025-10561 - Ubuntu version has reached the end of standard support

This CVE ID was assigned in error. The End-of-Life status of a component, by itself, does not constitute a vulnerability under the CVE Program’s rules. This condition represents a security weakness (CWE-1104: Use of Unmaintained Third-Party Components) rather than a specific vulnerability instanc…

📅 Published: Oct. 27, 2025, 10 a.m. 🔄 Last Modified: Nov. 11, 2025, 8:33 a.m.

8.7

CVSS4.0

CVE-2025-12258 - TOTOLINK A3300R POST Parameter cstecgi.cg setOpModeCfg stack-based overflow

A vulnerability was detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. Impacted is the function setOpModeCfg of the file /cgi-bin/cstecgi.cg of the component POST Parameter Handler. The manipulation of the argument opmode results in stack-based buffer overflow. The attack may be performed from rem…

📅 Published: Oct. 27, 2025, 9:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:09 a.m.

6.9

CVSS4.0

CVE-2025-12257 - SourceCodester Online Student Result System view_result.php sql injection

A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some unknown processing of the file /view_result.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been…

📅 Published: Oct. 27, 2025, 9:32 a.m. 🔄 Last Modified: Oct. 28, 2025, 2:10 a.m.

5.3

CVSS4.0

CVE-2025-12256 - code-projects Online Event Judging System edit_contestant.php sql injection

A weakness has been identified in code-projects Online Event Judging System 1.0. This vulnerability affects unknown code of the file /edit_contestant.php. Executing manipulation of the argument contestant_id can lead to sql injection. The attack can be executed remotely. The exploit has been made a…

📅 Published: Oct. 27, 2025, 9:32 a.m. 🔄 Last Modified: Oct. 28, 2025, 2:11 a.m.

5.3

CVSS3.1

CVE-2025-46583 - DOS Vulnerability in ZTE MC889A Pro product

There is a Denial of Service(DoS)vulnerability in the ZTE MC889A Pro product. Due to insufficient validation of the input parameters of the Short Message Service interface, allowing an attacker to exploit it to carry out a DoS attack.

📅 Published: Oct. 27, 2025, 9:23 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-12255 - code-projects Online Event Judging System add_contestant.php sql injection

A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown part of the file /add_contestant.php. Performing manipulation of the argument fullname results in sql injection. Remote exploitation of the attack is possible. The exploit has been released…

📅 Published: Oct. 27, 2025, 9:02 a.m. 🔄 Last Modified: Oct. 28, 2025, 2:11 a.m.

5.3

CVSS4.0

CVE-2025-12254 - code-projects Online Event Judging System add_judge.php sql injection

A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected by this issue is some unknown functionality of the file /add_judge.php. Such manipulation of the argument fullname leads to sql injection. The attack may be launched remotely. The exploit is publicly available…

📅 Published: Oct. 27, 2025, 9:02 a.m. 🔄 Last Modified: Oct. 28, 2025, 2:11 a.m.

6.9

CVSS4.0

CVE-2025-12253 - AMTT Hotel Broadband Operation System get_expiredtime.php sql injection

A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/portal/get_expiredtime.php. This manipulation of the argument uid causes sql injection. The attack may be initiated remotely. The exploit has bee…

📅 Published: Oct. 27, 2025, 9:02 a.m. 🔄 Last Modified: Oct. 28, 2025, 2:12 a.m.

6.9

CVSS4.0

CVE-2025-12080 - Intent Abuse in Google Messages for Wear OS for Silent Message Sending

On Wear OS devices, when Google Messages is configured as the default SMS/MMS/RCS application, the handling of ACTION_SENDTO intents utilizing the sms:, smsto:, mms:, and mmsto: Uniform Resource Identifier (URI) schemes is incorrectly implemented. Due to this misconfiguration, an attacker capable …

📅 Published: Oct. 27, 2025, 8:45 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3262 of 34,919
« previous page » next page
Filters