7.5

CVSS3.1

CVE-2025-56404 -

An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 8:32 p.m.

5.6

CVSS3.1

CVE-2025-57570 -

Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the QosList parameter in goform/setQoS.

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 8:59 p.m.

5.6

CVSS3.1

CVE-2025-57571 -

Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow. via the macFilterList parameter in goform/setNAT.

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 8:58 p.m.

5.6

CVSS3.1

CVE-2025-29592 -

oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:06 p.m.

8.8

CVSS3.1

CVE-2025-56407 -

A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/mysql.php. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. The exploit has been dis…

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: Oct. 6, 2025, 5:16 p.m.

7.5

CVSS3.1

CVE-2025-56406 -

An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE service. NOTE: the Supplier's position is that authentication is not mandatory for MCP servers, and the mcp-neo4j MCP server is only intended for use in a local en…

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-57642 -

A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the server, leading to remote code execution and unauthorized access to the system. This can result in the compromise of sensitive data and system functionality.

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 7:28 p.m.

5.6

CVSS3.1

CVE-2025-57572 -

Tenda F3 V12.01.01.48_multi and after is vulnerable to Buffer Overflow via the onlineList parameter in goform/setParentControl.

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 8:58 p.m.

8.8

CVSS3.1

CVE-2025-56413 -

OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /api/v2/hosts/ssh/operate endpoint.

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:41 p.m.

8.4

CVSS3.1

CVE-2025-55976 -

Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by querying this endpoint.

πŸ“… Published: Sept. 10, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 7:09 p.m.
Total resulsts: 349182
Page 3923 of 34,919
Β« previous page Β» next page
Filters