7.5

CVSS3.1

CVE-2025-24496 -

An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.

📅 Published: Aug. 20, 2025, 1:09 p.m. 🔄 Last Modified: Nov. 3, 2025, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-27129 -

An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.

📅 Published: Aug. 20, 2025, 1:09 p.m. 🔄 Last Modified: Nov. 3, 2025, 7:15 p.m.

8.6

CVSS3.1

CVE-2025-30256 -

A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted series of HTTP requests can lead to a reboot. An attacker can send multiple network packets to trigger this vulnerability.

📅 Published: Aug. 20, 2025, 1:09 p.m. 🔄 Last Modified: Nov. 3, 2025, 7:15 p.m.

8.1

CVSS3.1

CVE-2025-32010 -

A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP response can lead to arbitrary code execution. An attacker can send an HTTP response to trigger this vulnerability.

📅 Published: Aug. 20, 2025, 1:09 p.m. 🔄 Last Modified: Nov. 3, 2025, 7:15 p.m.

4.6

CVSS4.0

CVE-2025-54175 - Reflected Cross-Site Scripting in QuickCMS.EXT

QuickCMS.EXT is vulnerable to Reflected XSS in sFileName parameter in thumbnail viewer functionality.  An attacker can craft a malicious URL that results in arbitrary JavaScript execution in the victim's browser when opened. The vendor was notified early about this vulnerability, but didn't respon…

📅 Published: Aug. 20, 2025, 12:53 p.m. 🔄 Last Modified: Sept. 8, 2025, 5:08 p.m.

5.1

CVSS4.0

CVE-2025-54174 - Cross-Site Request Forgery in QuickCMS

QuickCMS is vulnerable to Cross-Site Request Forgery in article creation functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request creating a malicious article with content defined by the attacker. The vendor was notified e…

📅 Published: Aug. 20, 2025, 12:53 p.m. 🔄 Last Modified: Sept. 8, 2025, 5:08 p.m.

8.4

CVSS4.0

CVE-2025-8453 -

CWE-269: Improper Privilege Management vulnerability exists that could cause privilege escalation and arbitrary code execution when a privileged engineer user with console access modifies a configuration file used by a root-level daemon to execute custom scripts.

📅 Published: Aug. 20, 2025, 12:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-54172 - Stored Cross-Site Scripting in QuickCMS

QuickCMS is vulnerable to Stored XSS in sTitle parameter in page editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. Regular admin user is not able to inject any JS scripts into the …

📅 Published: Aug. 20, 2025, 12:52 p.m. 🔄 Last Modified: Sept. 8, 2025, 5:10 p.m.

5.3

CVSS4.0

CVE-2025-43749 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows unauthenticated users (guests) to access via URL files uploa…

📅 Published: Aug. 20, 2025, 12:32 p.m. 🔄 Last Modified: Dec. 16, 2025, 2:47 p.m.

5.1

CVSS4.0

CVE-2025-43750 -

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.1, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14 and 7.4 GA through update 92 allows remote unauthenticated users (guests) to upload files via th…

📅 Published: Aug. 20, 2025, 12:12 p.m. 🔄 Last Modified: Dec. 18, 2025, 2:45 p.m.
Total resulsts: 349182
Page 4200 of 34,919
« previous page » next page
Filters