7.5

CVSS3.1

CVE-2025-29421 - PerfreeBlog: From CVEorg collector

PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Aug. 26, 2025, 8:59 p.m.

9.8

CVSS3.1

CVE-2025-50722 -

Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Sept. 9, 2025, 6:57 p.m.

8.1

CVSS3.1

CVE-2025-50383 -

alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 7:59 p.m.

9.8

CVSS3.1

CVE-2025-45968 -

An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contains an Insecure Direct Object Reference (IDOR) vulnerability, which occurs due to a lack of proper authorization checks when accessing objects referenced by thi…

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 1:51 p.m.

6.5

CVSS3.1

CVE-2025-44178 -

DASAN GPON ONU H660WM H660WMR210825 is susceptible to improper access control under its default settings. Attackers can exploit this vulnerability to gain unauthorized access to sensitive information and modify its configuration via the UPnP protocol WAN sides without any authentication.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-29517 -

D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the traceroute6 function.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Sept. 2, 2025, 6:16 p.m.

9.8

CVSS3.1

CVE-2025-29515 -

Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modify arbitrary settings within the device's XML database, including the administrator’s password.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Sept. 2, 2025, 6:17 p.m.

5.1

CVSS3.1

CVE-2024-46413 -

Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.web.admin.rbstore.RBStoreController#loadDataIndex method.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 8:19 p.m.

6.5

CVSS3.1

CVE-2024-46412 -

Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a crafted GET request sent to /commons/ip-location.

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2023-47799 -

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account holders because the cac…

πŸ“… Published: Aug. 25, 2025, midnight πŸ”„ Last Modified: Sept. 5, 2025, 5:05 p.m.
Total resulsts: 349182
Page 4152 of 34,919
Β« previous page Β» next page
Filters