6.9

CVSS4.0

CVE-2025-7572 - LB-LINK BL-WR9000 lighttpd.cgi bs_GetHostInfo information disclosure

A vulnerability classified as critical was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. This vulnerability affects the function bs_GetHostInfo in the library libblinkapi.so of the file /cgi-bin/lighttpd.cgi. The manipulation leads to info…

📅 Published: July 14, 2025, 4:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-7571 - UTT HiPER 840G aspApBasicConfigUrcp buffer overflow

A vulnerability classified as critical has been found in UTT HiPER 840G up to 3.1.1-190328. This affects an unknown part of the file /goform/aspApBasicConfigUrcp. The manipulation of the argument Username leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been…

📅 Published: July 14, 2025, 4:14 a.m. 🔄 Last Modified: Jan. 8, 2026, 7:41 p.m.

8.7

CVSS4.0

CVE-2025-7570 - UTT HiPER 840G aspRemoteApConfTempSend buffer overflow

A vulnerability was found in UTT HiPER 840G up to 3.1.1-190328. It has been rated as critical. Affected by this issue is some unknown functionality of the file /goform/aspRemoteApConfTempSend. The manipulation of the argument remoteSrcTemp leads to buffer overflow. The attack may be launched remote…

📅 Published: July 14, 2025, 4:02 a.m. 🔄 Last Modified: Jan. 8, 2026, 7:42 p.m.

5.1

CVSS4.0

CVE-2025-7569 - Bigotry OneBase think_exception.tpl parse_args cross site scripting

A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerability is the function parse_args of the file /tpl/think_exception.tpl. The manipulation of the argument args leads to cross site scripting. The attack can be launched remotely. Th…

📅 Published: July 14, 2025, 3:44 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-7568 - qianfox FoxCMS Video.php batchCope sql injection

A vulnerability was found in qianfox FoxCMS up to 1.2.5. It has been classified as critical. Affected is the function batchCope of the file app/admin/controller/Video.php. The manipulation of the argument ids leads to sql injection. It is possible to launch the attack remotely. The exploit has been…

📅 Published: July 14, 2025, 3:32 a.m. 🔄 Last Modified: July 15, 2025, 6:31 p.m.

8.6

CVSS4.0

CVE-2025-7620 - DSIC|Cross-browser Components for Official Document Creation - Remote Code Execution

The cross-browser document creation component produced by Digitware System Integration Corporation has a Remote Code Execution vulnerability. If a user visits a malicious website while the component is active, remote attackers can cause the system to download and execute arbitrary programs.

📅 Published: July 14, 2025, 3:16 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-7567 - ShopXO header.html cross site scripting

A vulnerability was found in ShopXO up to 6.5.0 and classified as problematic. This issue affects some unknown processing of the file header.html. The manipulation of the argument lang/system_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to…

📅 Published: July 14, 2025, 3:14 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-7566 - jshERP SystemConfigController.java exportExcelByParam path traversal

A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file /src/main/java/com/jsh/erp/controller/SystemConfigController.java. The manipulation of the argument Title leads to path traversal. The attack can be …

📅 Published: July 14, 2025, 3:02 a.m. 🔄 Last Modified: Nov. 6, 2025, 6:59 p.m.

8.7

CVSS4.0

CVE-2025-7619 - WellChoose|BatchSignCS - Arbitrary File Write through Path Traversal

BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path and potentially lead to arbitrary code execution.

📅 Published: July 14, 2025, 3 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7565 - LB-LINK BL-AC3600 Web Management Interface lighttpd.cgi geteasycfg information disclosure

A vulnerability, which was classified as critical, was found in LB-LINK BL-AC3600 up to 1.0.22. This affects the function geteasycfg of the file /cgi-bin/lighttpd.cgi of the component Web Management Interface. The manipulation of the argument Password leads to information disclosure. It is possible…

📅 Published: July 14, 2025, 2:44 a.m. 🔄 Last Modified: July 17, 2025, 5:48 p.m.
Total resulsts: 345322
Page 4270 of 34,533
« previous page » next page
Filters