8.6

CVSS4.0

CVE-2025-12235 - Tenda CH22 SetIpBind fromSetIpBind buffer overflow

A vulnerability was found in Tenda CH22 1.0.0.1. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in buffer overflow. The attack must originate from the local network. The exploit has been made public and could be use…

πŸ“… Published: Oct. 27, 2025, 6:22 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:08 a.m.

8.7

CVSS4.0

CVE-2025-12234 - Tenda CH22 SafeMacFilter fromSafeMacFilter buffer overflow

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Oct. 27, 2025, 6:22 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:08 a.m.

8.7

CVSS4.0

CVE-2025-12233 - Tenda CH22 SafeUrlFilter fromSafeUrlFilter buffer overflow

A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

πŸ“… Published: Oct. 27, 2025, 6:22 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.

8.7

CVSS4.0

CVE-2025-12232 - Tenda CH22 SafeClientFilter fromSafeClientFilter buffer overflow

A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in buffer overflow. The attack can be initiated remotely. The exploit is now public an…

πŸ“… Published: Oct. 27, 2025, 6:22 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.

4.8

CVSS4.0

CVE-2025-12231 - projectworlds Expense Management System Expense Categories create cross site scripting

A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expense_categories/create of the component Expense Categories Page. Such manipulation leads to cross site scripting. It is possible to launch the atta…

πŸ“… Published: Oct. 27, 2025, 6:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:07 a.m.

4.8

CVSS4.0

CVE-2025-12230 - projectworlds Expense Management System Currency create cross site scripting

A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has …

πŸ“… Published: Oct. 27, 2025, 6:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.

5.4

CVSS3.1

CVE-2025-11154 - IDonate < 2.1.13 - Unauthenticated User Deletion

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated attackers to delete arbitrary users.

πŸ“… Published: Oct. 27, 2025, 6 a.m. πŸ”„ Last Modified: Dec. 5, 2025, 12:20 a.m.

4.8

CVSS4.0

CVE-2025-12229 - projectworlds Expense Management System Roles Page create cross site scripting

A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been re…

πŸ“… Published: Oct. 27, 2025, 5:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.

4.8

CVSS4.0

CVE-2025-12228 - projectworlds Expense Management System Users Page create cross site scripting

A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown function of the file /public/admin/users/create of the component Users Page. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The explo…

πŸ“… Published: Oct. 27, 2025, 5:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:07 a.m.

5.1

CVSS4.0

CVE-2025-12227 - projectworlds Gate Pass Management System add-pass.php cross site scripting

A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown function of the file /add-pass.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be …

πŸ“… Published: Oct. 27, 2025, 5:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.
Total resulsts: 349182
Page 3265 of 34,919
Β« previous page Β» next page
Filters