8.8

CVSS3.1

CVE-2025-45081 -

Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.

πŸ“… Published: July 1, 2025, midnight πŸ”„ Last Modified: July 3, 2025, 3:14 p.m.

9.8

CVSS3.1

CVE-2025-45872 -

zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.

πŸ“… Published: July 1, 2025, midnight πŸ”„ Last Modified: Aug. 14, 2025, 8:52 p.m.

9.8

CVSS3.1

CVE-2025-52101 -

linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attackers can bypass the authentication and retrieve the encrypted "password" and "salt". The password can then be obtained through brute-force cracking.

πŸ“… Published: July 1, 2025, midnight πŸ”„ Last Modified: July 3, 2025, 3:14 p.m.

6.5

CVSS3.1

CVE-2025-50405 -

Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation function.

πŸ“… Published: July 1, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 5:05 p.m.

5.3

CVSS3.1

CVE-2025-50404 -

Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processing the "command" field of the http header, causing the array to cross the boundary and overwrite other fields in the array.

πŸ“… Published: July 1, 2025, midnight πŸ”„ Last Modified: Aug. 20, 2025, 5:05 p.m.

9.1

CVSS3.1

CVE-2025-45006 -

Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential physical memory access attacks.

πŸ“… Published: July 1, 2025, midnight πŸ”„ Last Modified: July 3, 2025, 3:14 p.m.

6.1

CVSS3.1

CVE-2025-45083 -

Incorrect access control in Ullu (Android version v2.9.929 and IOS version v2.8.0) allows attackers to bypass parental pin feature via unspecified vectors.

πŸ“… Published: July 1, 2025, midnight πŸ”„ Last Modified: July 3, 2025, 3:14 p.m.

5.7

CVSS3.1

CVE-2025-52294 -

Insufficient validation of the screen lock mechanism in Trust Wallet v8.45 allows physically proximate attackers to bypass the lock screen and view the wallet balance.

πŸ“… Published: July 1, 2025, midnight πŸ”„ Last Modified: July 3, 2025, 3:14 p.m.

6.9

CVSS4.0

CVE-2025-6935 - Campcodes Sales and Inventory System payment_add.php sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/payment_add.php. The manipulation of the argument cid leads to sql injection. The attack may be launched remotely. The exploit ha…

πŸ“… Published: June 30, 2025, 11:32 p.m. πŸ”„ Last Modified: July 7, 2025, 2:46 p.m.

6.3

CVSS4.0

CVE-2025-6932 - D-Link DCS-7517 Qlync Password Generation httpd g_F_n_GenPassForQlync hard-coded password

A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the function g_F_n_GenPassForQlync of the file /bin/httpd of the component Qlync Password Generation Handler. The manipulation leads to use of hard-coded password. It is possible to initiat…

πŸ“… Published: June 30, 2025, 11:02 p.m. πŸ”„ Last Modified: July 14, 2025, 5:19 p.m.
Total resulsts: 343996
Page 4313 of 34,400
Β« previous page Β» next page
Filters