6.9

CVSS4.0

CVE-2025-54860 - Cognex In-Sight Explorer and In-Sight Camera Firmware Improper Restriction of Excessive Authenticaโ€ฆ

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow management operations on the device such as firmware upgrades and device reboot requiring an authentication. A wrong management of login failures of the service allows a denial-of-serโ€ฆ

๐Ÿ“… Published: Sept. 18, 2025, 9:20 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-53947 - Cognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Default Permissions

A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerability to corrupt sensitive data. A data folder is created with very weak privileges, allowing any user logged into the Windows system to modify its content.

๐Ÿ“… Published: Sept. 18, 2025, 9:10 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-47698 -

An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure.

๐Ÿ“… Published: Sept. 18, 2025, 9:07 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-54754 - Cognex In-Sight Explorer and In-Sight Camera Firmware Use of Hard-coded Password

An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then be used to decrypt sensitive network traffic, affecting the Cognex device.

๐Ÿ“… Published: Sept. 18, 2025, 9:06 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-30519 - Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak Credentials

Dover Fueling Solutions ProGauge MagLink LX4 Devicesย have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system.

๐Ÿ“… Published: Sept. 18, 2025, 8:46 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-54807 - Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Hard-coded Cryptographic Key

The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system.

๐Ÿ“… Published: Sept. 18, 2025, 8:44 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-55068 - Dover Fueling Solutions ProGauge MagLink LX4 Devices Integer Overflow or Wraparound

Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacker can manually change the system time to exploit this limitation, potentially causing errors in authentication and leading to a denial-of-service condition.

๐Ÿ“… Published: Sept. 18, 2025, 8:42 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-10689 - D-Link DIR-645 soap.cgi soapcgi_main command injection

A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. This vulnerabiโ€ฆ

๐Ÿ“… Published: Sept. 18, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Oct. 3, 2025, 5:26 p.m.

7.3

CVSS3.1

CVE-2025-59424 - LinkAce Vulnerable to Stored XSS on the Audit Page

LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. The application fails to properly sanitize the username field before it is rendered in the audit log. An authenticated attackerโ€ฆ

๐Ÿ“… Published: Sept. 18, 2025, 7:53 p.m. ๐Ÿ”„ Last Modified: Oct. 6, 2025, 3:03 p.m.

6.9

CVSS4.0

CVE-2025-10688 - SourceCodester Pet Grooming Management Software paid.php sql injection

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/operation/paid.php. This manipulation of the argument inv_no/insta_amt causes sql injection. The attack can be initiated remotely. The exploit has been pโ€ฆ

๐Ÿ“… Published: Sept. 18, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: Sept. 30, 2025, 3:11 p.m.
Total resulsts: 349182
Page 3777 of 34,919
ยซ previous page ยป next page
Filters