7.1

CVSS4.0

CVE-2025-11550 - Tenda W12 HTTP Request modules wifiScheduledSet null pointer dereference

A vulnerability was found in Tenda W12 3.0.0.6(3948). The impacted element is the function wifiScheduledSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument wifiScheduledSet results in null pointer dereference. The attack may be performed from remo…

📅 Published: Oct. 9, 2025, 6:02 p.m. 🔄 Last Modified: Oct. 9, 2025, 6:02 p.m.

8.7

CVSS4.0

CVE-2025-11573 - Denial of Service issue in Amazon.IonDotnet

An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not rec…

📅 Published: Oct. 9, 2025, 5:48 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:48 p.m.

8.7

CVSS4.0

CVE-2025-11549 - Tenda W12 HTTP Request modules wifiMacFilterSet stack-based overflow

A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the file /goform/modules of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. The attack is possible to be carried out rem…

📅 Published: Oct. 9, 2025, 5:02 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:02 p.m.

9.3

CVSS4.0

CVE-2017-20203 - NetSarang v5.0 Malicious Backdoor Supply Chain Compromise

NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT reco…

📅 Published: Oct. 9, 2025, 5:01 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:01 p.m.

0.0

CVE-2025-11371 - Gladinet CentreStack and TrioFox Local File Inclusion Flaw

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild.  This issue impacts Gladinet CentreStack and…

📅 Published: Oct. 9, 2025, 4:50 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:15 p.m.

5.3

CVSS4.0

CVE-2025-60010 - Junos OS and Junos OS Evolved: Device allows login for user with expired password

A password aging vulnerability in the RADIUS client of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to access the device without enforcing the required password change. Affected devices allow logins by users for whom the RADIUS server has responded…

📅 Published: Oct. 9, 2025, 4:20 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.

5.1

CVSS4.0

CVE-2025-60009 - Junos Space: CLI Configlet page is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the CLI Configlet page that, when visited by another user, enables the attacker to execute commands with the target's…

📅 Published: Oct. 9, 2025, 4:19 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.

4.8

CVSS4.0

CVE-2025-60006 - Junos OS Evolved: OS command injection vulnerabilities fixed

Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands. When an attacker executes crafted CLI comman…

📅 Published: Oct. 9, 2025, 4:18 p.m. 🔄 Last Modified: Oct. 10, 2025, 11:17 a.m.

8.7

CVSS4.0

CVE-2025-60004 - Junos OS and Junos OS Evolved: Specific BGP EVPN update message causes rpd crash

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial-Of-Service (DoS). When an affected system receives a specific BGP EVPN up…

📅 Published: Oct. 9, 2025, 4:18 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.

5.1

CVSS4.0

CVE-2025-60002 - Junos Space: Template Definitions page is vulnerable to reflected cross-site script injection

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the Template Definitions page that, when visited by another user, enables the attacker to execute commands with the targe…

📅 Published: Oct. 9, 2025, 4:17 p.m. 🔄 Last Modified: Oct. 9, 2025, 5:16 p.m.
Total resulsts: 313835
Page 35 of 31,384
« previous page » next page
Filters