6.9

CVSS4.0

CVE-2025-10973 - JackieDYH Resume-management-system show.php sql injection

A flaw has been found in JackieDYH Resume-management-system up to fb6b857d852dd796e748ce30c606fe5e61c18273. Affected by this issue is some unknown functionality of the file /admin/show.php. This manipulation of the argument userid causes sql injection. The attack may be initiated remotely. The expl…

πŸ“… Published: Sept. 25, 2025, 9:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-11005 - TOTOLINK X6000R Unauthenticated Command Injection Vulnerability

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1458_B20250708.

πŸ“… Published: Sept. 25, 2025, 8:17 p.m. πŸ”„ Last Modified: Oct. 16, 2025, 3:45 p.m.

6.9

CVSS4.0

CVE-2025-43816 -

A memory leak in the headless API for StructuredContents in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2024.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allow…

πŸ“… Published: Sept. 25, 2025, 8:02 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 6:20 p.m.

6.9

CVSS4.0

CVE-2025-10967 - MuFen-mker PHP-Usermm chkuser.php sql injection

A vulnerability was detected in MuFen-mker PHP-Usermm up to 37f2d24e51b04346dfc565b93fc2fc6b37bdaea9. This affects an unknown part of the file /chkuser.php. Performing manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit is now public and…

πŸ“… Published: Sept. 25, 2025, 8:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10965 - LazyAGI LazyLLM server.py lazyllm_call deserialization

A security vulnerability has been detected in LazyAGI LazyLLM up to 0.6.1. Affected by this issue is the function lazyllm_call of the file lazyllm/components/deploy/relay/server.py. Such manipulation leads to deserialization. The attack can be launched remotely. The exploit has been disclosed publi…

πŸ“… Published: Sept. 25, 2025, 8:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-43993 -

Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code Execution.

πŸ“… Published: Sept. 25, 2025, 7:38 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:05 p.m.

5.3

CVSS4.0

CVE-2025-10964 - Wavlink NU516U1 firewall.cgi sub_401B30 command injection

A weakness has been identified in Wavlink NU516U1. Affected by this vulnerability is the function sub_401B30 of the file /cgi-bin/firewall.cgi. This manipulation of the argument remoteManagementEnabled causes command injection. The attack can be initiated remotely. The exploit has been made availab…

πŸ“… Published: Sept. 25, 2025, 7:32 p.m. πŸ”„ Last Modified: Oct. 7, 2025, 8:50 p.m.

8.4

CVSS3.1

CVE-2025-59817 - Authenticated Remote Code Execution in zForm_auto_config

This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs with root privileges, successful exploitation grants full control over the device, potentially compromising its availability, confidentiality, and integrity.

πŸ“… Published: Sept. 25, 2025, 7:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-59816 - Authenticated Union based SQL-injection in the search input field

This vulnerability allows attackers to directly query the underlying database, potentially retrieving all data stored in the Billing Admin database, including user credentials. User passwords are stored in plaintext, significantly increasing the severity of this issue.

πŸ“… Published: Sept. 25, 2025, 7:30 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS3.1

CVE-2025-59815 - Authenticated Remote Code Execution in the Billing Administration portal

This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500 and ICX510 Gateway, granting shell access. Exploitation can compromise the device’s availability, confidentiality, and integrity.

πŸ“… Published: Sept. 25, 2025, 7:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3680 of 34,919
Β« previous page Β» next page
Filters