8.6

CVSS4.0

CVE-2013-10061 - Netgear Routers setup.cgi RCE

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware versions 1.1.00.24 and 1.1.00.45) via the TimeToLive parameter in the setup.cgi endpoint. The vulnerability arises from improper input neutralization, enabling command injection thro…

📅 Published: Aug. 1, 2025, 8:45 p.m. 🔄 Last Modified: April 7, 2026, 2:03 p.m.

9.3

CVSS4.0

CVE-2013-10047 - MiniWeb <= Build 300 Arbitrary File Upload

An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote attackers to upload arbitrary files to the server’s filesystem. By abusing the upload handler and crafting a traversal path, an attacker can place a malicious .exe in system32, fo…

📅 Published: Aug. 1, 2025, 8:45 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2013-10058 - Linksys Routers apply.cgi Remote Command Injection

An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) running firmware version v2.0.03 via the apply.cgi endpoint. The web interface fails to properly sanitize user-supplied input passed to the ping_size parameter during diagnostic operati…

📅 Published: Aug. 1, 2025, 8:44 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2013-10062 - Linksys Routers apply.cgi Path Traversal

A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware versions 1.0.00, 1.0.04, and 1.0.05), specifically in the /apply.cgi endpoint. Authenticated attackers can exploit the next_page POST parameter to access arbitrary files outside the inte…

📅 Published: Aug. 1, 2025, 8:44 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2012-10022 - Kloxo <= 6.1.12 Local Privilege Escalation

Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root if the invoking user matches uid 48. This flaw enables attackers …

📅 Published: Aug. 1, 2025, 8:42 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2013-10051 - InstantCMS <= 1.6 Remote PHP Code Execution

A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input passed via the look parameter is concatenated into a PHP expression and executed without proper sanitation. A remote a…

📅 Published: Aug. 1, 2025, 8:41 p.m. 🔄 Last Modified: April 7, 2026, 2:03 p.m.

9.3

CVSS4.0

CVE-2013-10055 - Havalite CMS Arbitary File Upload RCE

An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in the upload.php script. The application fails to enforce proper file extension validation and authentication checks, allowing remote attackers to upload malicious PHP files via a cra…

📅 Published: Aug. 1, 2025, 8:39 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2013-10048 - D-Link Devices command.php Unauthenticated RCE

An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending specially crafted POST requests, a remote attacker c…

📅 Published: Aug. 1, 2025, 8:39 p.m. 🔄 Last Modified: April 7, 2026, 2:03 p.m.

8.7

CVSS4.0

CVE-2013-10050 - D-Link Devices tools_vct.xgi Unauthenticated RCE

An OS command injection vulnerability exists in multiple D-Link routers—confirmed on DIR-300 rev A (v1.05) and DIR-615 rev D (v4.13)—via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly sanitize user-supplied input in the pingIp parameter, allowing attackers with va…

📅 Published: Aug. 1, 2025, 8:39 p.m. 🔄 Last Modified: April 7, 2026, 2:03 p.m.

8.6

CVSS4.0

CVE-2013-10059 - D-Link Routers tools_vct.htm OS Command Injection

An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowin…

📅 Published: Aug. 1, 2025, 8:38 p.m. 🔄 Last Modified: April 7, 2026, 2:03 p.m.
Total resulsts: 347837
Page 4300 of 34,784
« previous page » next page
Filters