8.7

CVSS4.0

CVE-2025-11386 - Tenda AC15 POST Parameter SetDDNSCfg stack-based overflow

A vulnerability was found in Tenda AC15 15.03.05.18. The impacted element is an unknown function of the file /goform/SetDDNSCfg of the component POST Parameter Handler. The manipulation of the argument ddnsEn results in stack-based buffer overflow. The attack can be launched remotely. The exploit h…

πŸ“… Published: Oct. 7, 2025, 10:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:47 a.m.

8.7

CVSS4.0

CVE-2025-11385 - Tenda AC20 fast_setting_wifi_set sscanf buffer overflow

A vulnerability has been found in Tenda AC20 up to 16.03.08.12. The affected element is the function sscanf of the file /goform/fast_setting_wifi_set. The manipulation of the argument timeZone leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the publ…

πŸ“… Published: Oct. 7, 2025, 9:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:47 a.m.

5.3

CVSS4.0

CVE-2025-11360 - jakowenko double-take API app.js app.use cross site scripting

A vulnerability was detected in jakowenko double-take up to 1.13.1. The impacted element is the function app.use of the file api/src/app.js of the component API. The manipulation of the argument X-Ingress-Path results in cross site scripting. The attack can be executed remotely. Upgrading to versio…

πŸ“… Published: Oct. 7, 2025, 9:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11359 - code-projects Simple Banking System transfermoney.php sql injection

A security vulnerability has been detected in code-projects Simple Banking System 1.0. The affected element is an unknown function of the file /transfermoney.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclose…

πŸ“… Published: Oct. 7, 2025, 8:32 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:46 p.m.

5.3

CVSS3.1

CVE-2025-10645 - WP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via wf-licensing.log

The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated attackers to extract sensitive license key and site data.

πŸ“… Published: Oct. 7, 2025, 8:23 a.m. πŸ”„ Last Modified: April 22, 2026, 1:15 p.m.

5.3

CVSS4.0

CVE-2025-11358 - code-projects Simple Banking System removeuser.php sql injection

A weakness has been identified in code-projects Simple Banking System 1.0. Impacted is an unknown function of the file /removeuser.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and cou…

πŸ“… Published: Oct. 7, 2025, 8:02 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:46 p.m.

5.3

CVSS4.0

CVE-2025-11357 - code-projects Simple Banking System createuser.php sql injection

A security flaw has been discovered in code-projects Simple Banking System 1.0. This issue affects some unknown processing of the file /createuser.php. Performing manipulation of the argument Name results in sql injection. The attack may be initiated remotely. The exploit has been released to the p…

πŸ“… Published: Oct. 7, 2025, 7:32 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:46 p.m.

6.4

CVSS3.1

CVE-2025-7400 - Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a post's Featured Image custom fields in all versions up to, and including, 5.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, …

πŸ“… Published: Oct. 7, 2025, 7:22 a.m. πŸ”„ Last Modified: April 20, 2026, 7:30 p.m.

8.7

CVSS4.0

CVE-2025-11356 - Tenda AC23 SetStaticRouteCfg sscanf buffer overflow

A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could …

πŸ“… Published: Oct. 7, 2025, 7:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:47 a.m.

8.7

CVSS4.0

CVE-2025-11355 - UTT 1250GW aspChangeChannel strcpy buffer overflow

A vulnerability has been found in UTT 1250GW up to v2v3.2.2-200710. Affected by this vulnerability is the function strcpy of the file /goform/aspChangeChannel. The manipulation of the argument pvid leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclo…

πŸ“… Published: Oct. 7, 2025, 6:32 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 4:02 p.m.
Total resulsts: 349182
Page 3525 of 34,919
Β« previous page Β» next page
Filters