6.1

CVSS3.1

CVE-2025-44595 -

Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 18, 2025, 8:33 p.m.

7.5

CVSS3.1

CVE-2025-57064 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 15, 2025, 6:14 p.m.

7.5

CVSS3.1

CVE-2025-57087 -

Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 18, 2025, 6:42 p.m.

7.5

CVSS3.1

CVE-2025-57071 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 18, 2025, 6:41 p.m.

7.5

CVSS3.1

CVE-2025-57062 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 18, 2025, 6:53 p.m.

7.5

CVSS3.1

CVE-2025-52322 -

An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to the SMF (PGW-C), using the IP address of a legitimate UE in the PDN Address Allocation (PAA) field

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 17, 2025, 8:19 p.m.

6.1

CVSS3.1

CVE-2025-44593 -

Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 18, 2025, 8:33 p.m.

9.1

CVSS3.1

CVE-2025-44594 -

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 17, 2025, 7:34 p.m.

7.5

CVSS3.1

CVE-2025-29089 -

An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 12, 2025, 9:11 a.m.

7.5

CVSS3.1

CVE-2025-57070 -

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

๐Ÿ“… Published: Sept. 9, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 18, 2025, 6:43 p.m.
Total resulsts: 349182
Page 3957 of 34,919
ยซ previous page ยป next page
Filters