1.8

CVSS4.0

CVE-2025-9806 - Tenda F1202 Administrative shadow hard-coded credentials

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high deg…

📅 Published: Sept. 2, 2025, 12:32 a.m. 🔄 Last Modified: Dec. 31, 2025, 12:48 a.m.

8.1

CVSS3.1

CVE-2025-57808 - ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP-IDF platform, ESPHome's web_server authentication check can pass incorrectly when the client-supplied base64-encoded Authorization value is empty or is a substring of the correct…

📅 Published: Sept. 2, 2025, 12:26 a.m. 🔄 Last Modified: Sept. 10, 2025, 7:03 p.m.

5.3

CVSS4.0

CVE-2025-9805 - SimStudioAI sim route.ts server-side request forgery

A vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This issue affects some unknown processing of the file apps/sim/app/api/proxy/image/route.ts. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit ha…

📅 Published: Sept. 2, 2025, 12:02 a.m. 🔄 Last Modified: Nov. 14, 2025, 8:34 p.m.

6.1

CVSS3.1

CVE-2025-55473 -

Asian Arts Talents Foundation (AATF) Website v5.1.x and Docker version 2024.12.8.1 are vulnerable to Cross Site Scripting (XSS). The vulnerability exists in the /ip.php endpoint, which processes and displays the X-Forwarded-For HTTP header without proper sanitization or output encoding. This allows…

📅 Published: Sept. 2, 2025, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2025-9714 - Stack overflow in libxml2

Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a stack overflow via crafted expressions. XPath processing functions `xmlXPathRunEval`, `xmlXPathCtxtCompile`, and `xmlXPathEvalExpr` were resetting recursion depth to zero befo…

📅 Published: Sept. 2, 2025, midnight 🔄 Last Modified: Nov. 3, 2025, 7:16 p.m.

6.5

CVSS3.1

CVE-2024-48705 -

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santizat…

📅 Published: Sept. 2, 2025, midnight 🔄 Last Modified: Sept. 4, 2025, 5:47 p.m.

6.5

CVSS3.1

CVE-2025-46047 -

A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter.

📅 Published: Sept. 2, 2025, midnight 🔄 Last Modified: Sept. 4, 2025, 5:46 p.m.

5.3

CVSS3.1

CVE-2025-55372 -

An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

📅 Published: Sept. 2, 2025, midnight 🔄 Last Modified: Sept. 11, 2025, 9:17 p.m.

5.3

CVSS3.1

CVE-2025-57611 -

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the dump() method allows an attacker to cause a denial of service. The vulnerability exists because the method fails to check the return value of avfilter_graph_dump() for NULL, leading to a…

📅 Published: Sept. 2, 2025, midnight 🔄 Last Modified: Sept. 10, 2025, 6:36 p.m.

6.5

CVSS3.1

CVE-2025-55476 -

FireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint: GET /api/videos/public?sort= This parameter is unsafely evaluated in a SQL ORDER BY clause without proper sanitization, allowing an attacker to inject arbitrary SQL subqueries.

📅 Published: Sept. 2, 2025, midnight 🔄 Last Modified: Sept. 5, 2025, 6:10 p.m.
Total resulsts: 349182
Page 4058 of 34,919
« previous page » next page
Filters