9.8

CVSS3.1

CVE-2025-46121 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either b…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 5:18 p.m.

4.6

CVSS3.1

CVE-2025-52373 -

Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 6 p.m.

5.1

CVSS3.1

CVE-2025-52372 -

An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss and hMailServer.ini components.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 8, 2025, 4:19 p.m.

9.8

CVSS3.1

CVE-2025-46120 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a rem…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 5:18 p.m.

9.1

CVSS3.1

CVE-2025-46117 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 5:17 p.m.

7.5

CVSS3.1

CVE-2025-44652 -

In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 9:04 p.m.

7.5

CVSS3.1

CVE-2025-51869 -

Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, thread_id, and message_id parameters to the v1/space/{space_id}/thread/{thread_id}/message/{message_id} endpoint.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-7777 - Mirror-registry: host header injection in mirror-registry

The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or phishing campaigns.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-44655 -

In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 5:58 p.m.

9.8

CVSS3.1

CVE-2025-36846 -

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed directly into the shell_exec() function of PHP. …

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 5:58 p.m.
Total resulsts: 346618
Page 4322 of 34,662
Β« previous page Β» next page
Filters