9.8

CVSS3.1

CVE-2025-50428 -

In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.

πŸ“… Published: Aug. 27, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:45 p.m.

6.5

CVSS3.1

CVE-2025-55495 -

Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.

πŸ“… Published: Aug. 27, 2025, midnight πŸ”„ Last Modified: Sept. 3, 2025, 4:11 p.m.

9.8

CVSS3.1

CVE-2025-52122 -

Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).

πŸ“… Published: Aug. 27, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:53 p.m.

5.6

CVSS3.1

CVE-2025-50986 -

diskover-web v2.3.0 Community Edition suffers from multiple stored cross-site scripting (XSS) vulnerabilities in its administrative settings interface. Various configuration fields such as ES_HOST, ES_INDEXREFRESH, ES_PORT, ES_SCROLLSIZE, ES_TRANSLOGSIZE, ES_TRANSLOGSYNCINT, EXCLUDES_FILES, FILE_TY…

πŸ“… Published: Aug. 27, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:53 p.m.

7.3

CVSS3.1

CVE-2025-55618 -

In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field in navigation app which then get rendered.

πŸ“… Published: Aug. 27, 2025, midnight πŸ”„ Last Modified: April 6, 2026, 2:23 p.m.

6.5

CVSS3.1

CVE-2025-54598 -

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.

πŸ“… Published: Aug. 27, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:46 p.m.

4.4

CVSS3.1

CVE-2025-8490 - All-in-One WP Migration and Backup <= 7.97 - Authenticated (Administrator+) Stored Cross-Site Scrip…

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Import in all versions up to, and including, 7.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

πŸ“… Published: Aug. 26, 2025, 11:22 p.m. πŸ”„ Last Modified: April 21, 2026, 7:15 p.m.

4

CVSS3.1

CVE-2025-26417 -

In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for e…

πŸ“… Published: Aug. 26, 2025, 10:48 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:59 p.m.

4

CVSS3.1

CVE-2025-22413 -

In multiple functions of hyp-main.c, there is a possible privilege escalation due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Aug. 26, 2025, 10:48 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:59 p.m.

8.8

CVSS3.1

CVE-2025-22412 -

In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Aug. 26, 2025, 10:48 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.
Total resulsts: 349182
Page 4129 of 34,919
Β« previous page Β» next page
Filters