6.5

CVSS3.1

CVE-2025-57428 -

Default credentials in Each Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and execute hardware-level flash and register manipulation commands.

πŸ“… Published: Sept. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9

CVSS3.1

CVE-2025-56795 -

Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.

πŸ“… Published: Sept. 29, 2025, midnight πŸ”„ Last Modified: Oct. 16, 2025, 3:42 p.m.

6

CVSS3.1

CVE-2025-57197 -

In the Payeer Android application 2.5.0, an improper access control vulnerability exists in the authentication flow for the PIN change feature. A local attacker with root access to the device can dynamically instrument the app to bypass the current PIN verification check and directly modify the aut…

πŸ“… Published: Sept. 29, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-11125 - langleyfcu Online Banking System Error Message connection_error.php cross site scripting

A vulnerability was found in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. Affected by this vulnerability is an unknown functionality of the file /connection_error.php of the component Error Message Handler. Performing manipulation of the argument Error results in…

πŸ“… Published: Sept. 28, 2025, 11:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-11124 - code-projects Project Monitoring System postjob.php cross site scripting

A vulnerability has been found in code-projects Project Monitoring System 1.0. Affected is an unknown function of the file /onlineJobSearchEngine/postjob.php. Such manipulation of the argument txtapplyto leads to cross site scripting. The attack may be launched remotely. The exploit has been disclo…

πŸ“… Published: Sept. 28, 2025, 11:02 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

8.7

CVSS4.0

CVE-2025-11123 - Tenda AC18 saveAutoQos stack-based overflow

A flaw has been found in Tenda AC18 15.03.05.19. This impacts an unknown function of the file /goform/saveAutoQos. This manipulation of the argument enable causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used.

πŸ“… Published: Sept. 28, 2025, 10:32 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 1:46 p.m.

8.7

CVSS4.0

CVE-2025-11122 - Tenda AC18 WizardHandle stack-based overflow

A vulnerability was detected in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandle. The manipulation of the argument WANT/mtuvalue results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.

πŸ“… Published: Sept. 28, 2025, 10:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 1:46 p.m.

5.3

CVSS4.0

CVE-2025-11121 - Tenda AC18 AdvSetLanip command injection

A security vulnerability has been detected in Tenda AC18 15.03.05.19. The impacted element is an unknown function of the file /goform/AdvSetLanip. The manipulation of the argument lanIp leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may…

πŸ“… Published: Sept. 28, 2025, 9:32 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 1:45 p.m.

8.7

CVSS4.0

CVE-2025-11120 - Tenda AC8 SetServerConfig formSetServerConfig buffer overflow

A weakness has been identified in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the file /goform/SetServerConfig. Executing manipulation can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public …

πŸ“… Published: Sept. 28, 2025, 9:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 1:42 p.m.

5.3

CVSS4.0

CVE-2025-11119 - itsourcecode Hostel Management System POST Request index.php cross site scripting

A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST Request Handler. Performing manipulation of the argument from results in cross site scripting. It is possible to initiate the attac…

πŸ“… Published: Sept. 28, 2025, 8:32 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 1:40 p.m.
Total resulsts: 349182
Page 3650 of 34,919
Β« previous page Β» next page
Filters