7.3

CVSS4.0

CVE-2025-8758 - TRENDnet TEW-822DRE vsftpd least privilege violation

A vulnerability was found in TRENDnet TEW-822DRE FW103B02. It has been classified as problematic. This affects an unknown part of the component vsftpd. The manipulation leads to least privilege violation. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitabi…

📅 Published: Aug. 9, 2025, 4:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-8757 - TRENDnet TV-IP110WN Embedded Boa Web Server boa.conf least privilege violation

A vulnerability was found in TRENDnet TV-IP110WN 1.2.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /server/boa.conf of the component Embedded Boa Web Server. The manipulation leads to least privilege violation. Local access is required to approach…

📅 Published: Aug. 9, 2025, 3:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-8756 - TDuckCloud tduck-platform manage preHandle improper authorization

A vulnerability has been found in TDuckCloud tduck-platform up to 5.1 and classified as critical. Affected by this vulnerability is the function preHandle of the file /manage/ of the component com.tduck.cloud.api.web.interceptor.AuthorizationInterceptor. The manipulation leads to improper authoriza…

📅 Published: Aug. 9, 2025, 2:32 p.m. 🔄 Last Modified: Sept. 11, 2025, 5:10 p.m.

6.9

CVSS4.0

CVE-2025-8755 - macrozheng mall com.macro.mall.portal.controller UmsMemberController.java detail authorization

A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberController.java of the component com.macro.mall.portal.controller. The manipulation of the argument orderId leads to authorization bypass. The attack m…

📅 Published: Aug. 9, 2025, 2:02 p.m. 🔄 Last Modified: Sept. 2, 2025, 7:23 p.m.

6.4

CVSS3.1

CVE-2025-7726 - The7 <= 12.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via title and data-dt-img…

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via its lightbox rendering code in all versions up to, and including, 12.6.0 due to insufficient input sanitization and output escaping. The theme’s JavaScript reads user-supplied 'title' and 'data-dt-img-description' attribu…

📅 Published: Aug. 9, 2025, 1:45 p.m. 🔄 Last Modified: April 21, 2026, 3:45 a.m.

5.3

CVSS4.0

CVE-2025-8753 - linlinjava litemall File delete path traversal

A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this issue is the function delete of the file /admin/storage/delete of the component File Handler. The manipulation of the argument key leads to path traversal. The attack may be launch…

📅 Published: Aug. 9, 2025, 1:32 p.m. 🔄 Last Modified: Sept. 11, 2025, 2:56 p.m.

5.1

CVSS4.0

CVE-2025-7020 - BYD DiLink OS Incorrect encryption Implementation of system log dumps

An incorrect encryption implementation vulnerability exists in the system log dump feature of BYD's DiLink 3.0 OS (e.g. in the model ATTO3). An attacker with physical access to the vehicle can bypass the encryption of log dumps on the In-Vehicle Infotainment (IVI) unit's storage. This allows the at…

📅 Published: Aug. 9, 2025, 12:42 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-8752 - wangzhixuan spring-shiro-training add command injection

A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has been declared as critical. This vulnerability affects unknown code of the file /role/add. The manipulation leads to command injection. The attack can be initiated remotely. The expl…

📅 Published: Aug. 9, 2025, 12:02 p.m. 🔄 Last Modified: Sept. 16, 2025, 3:25 p.m.

2.3

CVSS4.0

CVE-2025-8751 - Protected Total WebShield Extension Block Page cross site scripting

A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has been classified as problematic. This affects an unknown part of the component Block Page. The manipulation of the argument Category leads to cross site scripting. It is possible to initiate the attack rem…

📅 Published: Aug. 9, 2025, 7:32 a.m. 🔄 Last Modified: Sept. 16, 2025, 3:32 p.m.

4.8

CVSS4.0

CVE-2025-8750 - macrozheng mall Add Product Page upload cross site scripting

A vulnerability has been found in macrozheng mall up to 1.0.3 and classified as problematic. Affected by this vulnerability is the function Upload of the file /minio/upload of the component Add Product Page. The manipulation of the argument File leads to cross site scripting. The attack can be laun…

📅 Published: Aug. 9, 2025, 7:02 a.m. 🔄 Last Modified: Sept. 2, 2025, 7:23 p.m.
Total resulsts: 347679
Page 4211 of 34,768
« previous page » next page
Filters