5.3

CVSS4.0

CVE-2025-7167 - code-projects Responsive Blog Site category.php sql injection

A vulnerability was found in code-projects Responsive Blog Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /category.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed โ€ฆ

๐Ÿ“… Published: July 8, 2025, 7:02 a.m. ๐Ÿ”„ Last Modified: July 9, 2025, 1:48 p.m.

8.8

CVSS3.1

CVE-2025-25271 - OCPP Backend Configuration via Insecure Defaults

An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.

๐Ÿ“… Published: July 8, 2025, 7:01 a.m. ๐Ÿ”„ Last Modified: July 22, 2025, 7:50 a.m.

9.8

CVSS3.1

CVE-2025-25270 - Remote Code Execution via Unauthenticated Configuration Manipulation

An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.

๐Ÿ“… Published: July 8, 2025, 7 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 2:37 p.m.

8.4

CVSS3.1

CVE-2025-25269 - Local Privilege Escalation via Unauthenticated Command Injection

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

๐Ÿ“… Published: July 8, 2025, 7 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 2:37 p.m.

8.8

CVSS3.1

CVE-2025-25268 - Unauthenticated Configuration Access via Exposed API Endpoint

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.

๐Ÿ“… Published: July 8, 2025, 7 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 2:37 p.m.

7.8

CVSS3.1

CVE-2025-24006 - Privilege Escalation via Insecure SSH Permissions

A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.

๐Ÿ“… Published: July 8, 2025, 7 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 2:36 p.m.

7.8

CVSS3.1

CVE-2025-24005 - Local Privilege Escalation via Vulnerable SSH Script

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.

๐Ÿ“… Published: July 8, 2025, 6:59 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 2:36 p.m.

5.2

CVSS3.1

CVE-2025-24004 - USB-C Buffer Overflow via Display Interface in EV Charging Stations

A physical attacker with access to the device display via USB-C can send a message to the device which triggers an unsecure copy to a buffer resulting in loss of integrity and a temporary denial-of-service for the stations until they got restarted by the watchdog.

๐Ÿ“… Published: July 8, 2025, 6:59 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 2:36 p.m.

8.2

CVSS3.1

CVE-2025-24003 - MQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging Stations

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying with German Calibration Law, resulting in a loss of integrity for only EichrechtAgents and potential denial-of-service for these stations.

๐Ÿ“… Published: July 8, 2025, 6:59 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 2:36 p.m.

5.3

CVSS3.1

CVE-2025-24002 - MQTT DoS Vulnerability in German EV Charging Stations

An unauthenticated remote attacker can use MQTT messages to crash a service on charging stations complying with German Calibration Law, resulting in a temporary denial-of-service for these stations until they got restarted by the watchdog.

๐Ÿ“… Published: July 8, 2025, 6:58 a.m. ๐Ÿ”„ Last Modified: July 11, 2025, 2:36 p.m.
Total resulsts: 346087
Page 4441 of 34,609
ยซ previous page ยป next page
Filters