7.5

CVSS3.1

CVE-2023-28760 -

TP-Link AX1800 WiFi 6 Router (Archer AX21) devices allow unauthenticated attackers (on the LAN) to execute arbitrary code as root via the db_dir field to minidlnad. The attacker obtains the ability to modify files.db, and that can be used to reach a stack-based buffer overflow in minidlna-1.1.2/upn…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-61096 -

PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 6:14 p.m.

5.4

CVSS3.1

CVE-2025-60782 -

PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability in the topics management module (topics.php). Attackers can inject malicious JavaScript payloads into the Titlefield during topic creation or updates.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 6:14 p.m.

7.5

CVSS3.1

CVE-2025-60660 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the mac parameter in the fromAdvSetMacMtuWan function.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 7, 2025, 5:44 p.m.

7.5

CVSS3.1

CVE-2025-59409 -

Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 24, 2025, 5:23 p.m.

9.8

CVSS3.1

CVE-2025-59407 -

The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a Java Keystore (flock_rye.bks) along with its hardcoded password (flockhibiki17) in its code. The k…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 24, 2025, 5:26 p.m.

7.5

CVSS3.1

CVE-2025-59405 -

The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a cleartext DataDog API key within in its codebase. Because application binaries can be trivially decompil…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 2:29 p.m.

9.8

CVSS3.1

CVE-2025-59403 -

The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoints on port 8080 without authentication. Endpoints include b…

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 3:15 p.m.

6.5

CVSS3.1

CVE-2025-56381 -

ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 4:18 p.m.

5.4

CVSS3.1

CVE-2025-56379 -

A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the content field.

πŸ“… Published: Oct. 2, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 7:15 p.m.
Total resulsts: 349182
Page 3599 of 34,919
Β« previous page Β» next page
Filters