6.9
CVE-2025-54860 - Cognex In-Sight Explorer and In-Sight Camera Firmware Improper Restriction of Excessive Authenticaโฆ
Cognex In-Sight Explorer and In-Sight Camera Firmware expose a telnet-based service on port 23 in order to allow management operations on the device such as firmware upgrades and device reboot requiring an authentication. A wrong management of login failures of the service allows a denial-of-serโฆ
6.9
CVE-2025-53947 - Cognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Default Permissions
A local attacker with low privileges on the Windows system where the software is installed can exploit this vulnerability to corrupt sensitive data. A data folder is created with very weak privileges, allowing any user logged into the Windows system to modify its content.
8.6
CVE-2025-47698 -
An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure.
8.6
CVE-2025-54754 - Cognex In-Sight Explorer and In-Sight Camera Firmware Use of Hard-coded Password
An attacker with adjacent access, without authentication, can exploit this vulnerability to retrieve a hard-coded password embedded in publicly available software. This password can then be used to decrypt sensitive network traffic, affecting the Cognex device.
9.3
CVE-2025-30519 - Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Weak Credentials
Dover Fueling Solutions ProGauge MagLink LX4 Devicesย have default root credentials that cannot be changed through standard administrative means. An attacker with network access to the device can gain administrative access to the system.
9.3
CVE-2025-54807 - Dover Fueling Solutions ProGauge MagLink LX4 Devices Use of Hard-coded Cryptographic Key
The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system.
8.8
CVE-2025-55068 - Dover Fueling Solutions ProGauge MagLink LX4 Devices Integer Overflow or Wraparound
Dover Fueling Solutions ProGauge MagLink LX4 Devices fail to handle Unix time values beyond a certain point. An attacker can manually change the system time to exploit this limitation, potentially causing errors in authentication and leading to a denial-of-service condition.
5.3
CVE-2025-10689 - D-Link DIR-645 soap.cgi soapcgi_main command injection
A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap.cgi. Such manipulation of the argument service leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. This vulnerabiโฆ
7.3
CVE-2025-59424 - LinkAce Vulnerable to Stored XSS on the Audit Page
LinkAce is a self-hosted archive to collect website links. Prior to 2.3.1, a Stored Cross-Site Scripting (XSS) vulnerability has been identified on the /system/audit page. The application fails to properly sanitize the username field before it is rendered in the audit log. An authenticated attackerโฆ
6.9
CVE-2025-10688 - SourceCodester Pet Grooming Management Software paid.php sql injection
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/operation/paid.php. This manipulation of the argument inv_no/insta_amt causes sql injection. The attack can be initiated remotely. The exploit has been pโฆ