5.3

CVSS4.0

CVE-2025-10780 - CodeAstro Simple Pharmacy Management view.php sql injection

A vulnerability was determined in CodeAstro Simple Pharmacy Management 1.0. This affects an unknown function of the file /view.php. This manipulation of the argument bar_code causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be util…

πŸ“… Published: Sept. 22, 2025, 3:32 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 7:58 p.m.

8.7

CVSS4.0

CVE-2025-10779 - D-Link DCS-935L HNAP1 sub_402280 stack-based overflow

A vulnerability was found in D-Link DCS-935L up to 1.13.01. The impacted element is the function sub_402280 of the file /HNAP1/. The manipulation of the argument HNAP_AUTH/SOAPAction results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and co…

πŸ“… Published: Sept. 22, 2025, 3:02 a.m. πŸ”„ Last Modified: Sept. 25, 2025, 8:01 p.m.

2.3

CVSS4.0

CVE-2025-10778 - Smartstore Gift Voucher confirm race condition

A vulnerability has been found in Smartstore up to 6.2.0. The affected element is an unknown function of the file /checkout/confirm/ of the component Gift Voucher Handler. The manipulation leads to race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The e…

πŸ“… Published: Sept. 22, 2025, 2:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10777 - JSC R7 R7-Office Document Server downloadas path traversal

A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown function of the file /downloadas/. Executing manipulation of the argument cmd can lead to path traversal. The attack can be launched remotely. Upgrading to version 2025.3.1.923 is recommended to address…

πŸ“… Published: Sept. 22, 2025, 2:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-10776 - LionCoders SalePro POS Login cleartext transmission

A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the component Login. Performing manipulation results in cleartext transmission of sensitive information. The attack can be initiated remotely. The attack is considered to have high comp…

πŸ“… Published: Sept. 22, 2025, 1:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-10775 - Wavlink WL-NU516U1 login.cgi sub_4012A0 os command injection

A security vulnerability has been detected in Wavlink WL-NU516U1 240425. This vulnerability affects the function sub_4012A0 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to os command injection. It is possible to launch the attack remotely. The exploit has been disc…

πŸ“… Published: Sept. 22, 2025, 1:02 a.m. πŸ”„ Last Modified: Oct. 7, 2025, 8:47 p.m.

5.1

CVSS4.0

CVE-2025-10774 - Ruijie 6000-E10 sub_commit.php os command injection

A weakness has been identified in Ruijie 6000-E10 up to 2.4.3.6-20171117. This affects an unknown part of the file /view/vpn/autovpn/sub_commit.php. This manipulation of the argument key causes os command injection. It is possible to initiate the attack remotely. The exploit has been made available…

πŸ“… Published: Sept. 22, 2025, 12:32 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-10773 - B-Link BL-AC2100 Web Management set_delshrpath_cfg delshrpath stack-based overflow

A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath of the file /goform/set_delshrpath_cfg of the component Web Management Interface. The manipulation of the argument Type results in stack-based buffer overflow. The attack may be pe…

πŸ“… Published: Sept. 22, 2025, 12:02 a.m. πŸ”„ Last Modified: Sept. 30, 2025, 6:15 p.m.

5.4

CVSS3.1

CVE-2025-52367 -

Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Oct. 24, 2025, 2:45 p.m.

9.8

CVSS3.1

CVE-2025-57441 -

The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can access a protocol preamble that leaks the video mode, routing configuration, input/output labels, device model, and ev…

πŸ“… Published: Sept. 22, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 8:34 p.m.
Total resulsts: 349182
Page 3756 of 34,919
Β« previous page Β» next page
Filters