5.3

CVSS4.0

CVE-2025-46704 - Advantech iView Path Traversal

A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properly sanitized or normalized, potentially allo…

πŸ“… Published: July 10, 2025, 11:19 p.m. πŸ”„ Last Modified: July 23, 2025, 7:20 p.m.

7.2

CVSS4.0

CVE-2025-48891 - Advantech iView SQL Injection

A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure or a denial-of-servic…

πŸ“… Published: July 10, 2025, 11:17 p.m. πŸ”„ Last Modified: July 23, 2025, 7:20 p.m.

5.1

CVSS4.0

CVE-2025-41442 - Advantech iView Cross-site Scripting

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disc…

πŸ“… Published: July 10, 2025, 11:15 p.m. πŸ”„ Last Modified: July 23, 2025, 7:20 p.m.

5.1

CVSS4.0

CVE-2025-53519 - Advantech iView Cross-site Scripting

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosur…

πŸ“… Published: July 10, 2025, 11:14 p.m. πŸ”„ Last Modified: July 23, 2025, 7:19 p.m.

5.1

CVSS4.0

CVE-2025-53397 - Advantech iView Cross-site Scripting

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other m…

πŸ“… Published: July 10, 2025, 11:13 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 7:19 p.m.

8.7

CVSS4.0

CVE-2025-7419 - Tenda O3V2 httpd setRateTest fromSpeedTestSet stack-based overflow

A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fromSpeedTestSet of the file /goform/setRateTest of the component httpd. The manipulation of the argument destIP leads to stack-based buffer overflow. It is possible to initiate the…

πŸ“… Published: July 10, 2025, 11:02 p.m. πŸ”„ Last Modified: July 16, 2025, 4:40 p.m.

7.2

CVSS4.0

CVE-2025-1727 - End-of-Train and Head-of-Train Remote Linking Protocol Weak Authentication

The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH checksum for packet creation. It is possible to create these EoT and HoT packets with a software defined radio and issue brake control commands to the EoT device, disrupting op…

πŸ“… Published: July 10, 2025, 10:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-7418 - Tenda O3V2 httpd setPing fromPingResultGet stack-based overflow

A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the function fromPingResultGet of the file /goform/setPing of the component httpd. The manipulation of the argument destIP leads to stack-based buffer overflow. The attack may be launched re…

πŸ“… Published: July 10, 2025, 10:32 p.m. πŸ”„ Last Modified: July 16, 2025, 4:41 p.m.

4.6

CVSS3.1

CVE-2025-31267 -

An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.

πŸ“… Published: July 10, 2025, 10:23 p.m. πŸ”„ Last Modified: April 2, 2026, 6:20 p.m.

8.7

CVSS4.0

CVE-2025-7417 - Tenda O3V2 httpd setPingInfo fromNetToolGet stack-based overflow

A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability is the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be l…

πŸ“… Published: July 10, 2025, 10:02 p.m. πŸ”„ Last Modified: July 16, 2025, 4:41 p.m.
Total resulsts: 345192
Page 4282 of 34,520
Β« previous page Β» next page
Filters