5.4

CVSS3.1

CVE-2025-57538 -

A stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual Environment (PVE) 8.4 allows an authenticated user to inject malicious input. The input is stored and executed in the context of other users' browsers when they vie…

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 18, 2025, 5:41 p.m.

8.8

CVSS3.1

CVE-2025-57278 -

The LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session handling. After a user authenticates from a specific IP address, the router grants access to any other client using that same IP, without requiring credentials or ver…

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 5:56 p.m.

3.1

CVSS3.1

CVE-2025-8277 - Libssh: memory exhaustion via repeated key exchange in libssh

A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This issue can lead to crashes on the client side, particularly when…

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: May 6, 2026, 3:12 p.m.

7.5

CVSS3.1

CVE-2025-57059 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 15, 2025, 6:14 p.m.

9.8

CVSS3.1

CVE-2025-57633 -

A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute arbitrary OS commands. The /ftp.html endpoint's "Upload File" action constructs a shell command from the ftp_file parameter and executes it using os.system() without sanitization…

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 11, 2025, 5:14 p.m.

9.8

CVSS3.1

CVE-2025-57085 -

Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 17, 2025, 7:50 p.m.

7.5

CVSS3.1

CVE-2025-57072 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 18, 2025, 6:38 p.m.

7.5

CVSS3.1

CVE-2025-57063 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 15, 2025, 6:14 p.m.

7.5

CVSS3.1

CVE-2025-57061 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip, mac, v6 and remark parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 15, 2025, 6:14 p.m.

7.2

CVSS3.1

CVE-2025-52915 -

K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling…

πŸ“… Published: Sept. 9, 2025, midnight πŸ”„ Last Modified: Sept. 10, 2025, 2:15 p.m.
Total resulsts: 349182
Page 3956 of 34,919
Β« previous page Β» next page
Filters