9.3

CVSS4.0

CVE-2012-10021 - D-Link DIR-605L Captcha Handling Buffer Overflow

A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via the FILECODE parameter in /goform/formLogin.…

📅 Published: July 31, 2025, 2:54 p.m. 🔄 Last Modified: April 7, 2026, 2:02 p.m.

10

CVSS4.0

CVE-2013-10040 - ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE

ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file…

📅 Published: July 31, 2025, 2:53 p.m. 🔄 Last Modified: March 23, 2026, 3:43 p.m.

8.4

CVSS4.0

CVE-2013-10036 - Beetel Connection Manager NetConfig.ini Stack-Based Buffer Overflow

A stack-based buffer overflow vulnerability exists in Beetel Connection Manager version PCW_BTLINDV1.0.0B04 when parsing the UserName parameter in the NetConfig.ini configuration file. A crafted .ini file containing an overly long UserName value can overwrite the Structured Exception Handler (SEH),…

📅 Published: July 31, 2025, 2:53 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.5

CVSS4.0

CVE-2013-10043 - Astium VOIP PBX <= 2.1 SQL Injection File Upload RCE

A vulnerability exists in OAstium VoIP PBX astium-confweb-2.1-25399 and earlier, where improper input validation in the logon.php script allows an attacker to bypass authentication via SQL injection. Once authenticated as an administrator, the attacker can upload arbitrary PHP code through the impo…

📅 Published: July 31, 2025, 2:53 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2014-125121 - Array Networks vAPV and vxAG Default Credential Privilege Escalation

Array Networks vAPV (version 8.3.2.17) and vxAG (version 9.2.0.34) appliances are affected by a privilege escalation vulnerability caused by a combination of hardcoded SSH credentials (or SSH private key) and insecure permissions on a startup script. The devices ship with a default SSH login or a h…

📅 Published: July 31, 2025, 2:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2014-125125 - A10 Networks AX Loadbalancer Path Traversal

A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vulnerability resides in the handling of the filename parameter in the /xml/downloads endpoint, which fails to properly sanitize user input. An unauthenticated attacker can exploit t…

📅 Published: July 31, 2025, 2:50 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-8407 - code-projects Vehicle Management filter2.php sql injection

A vulnerability, which was classified as critical, has been found in code-projects Vehicle Management 1.0. This issue affects some unknown processing of the file /filter2.php. The manipulation of the argument from leads to sql injection. The attack may be initiated remotely. The exploit has been di…

📅 Published: July 31, 2025, 2:02 p.m. 🔄 Last Modified: Aug. 5, 2025, 8:45 p.m.

6.3

CVSS3.1

CVE-2025-54589 - copyparty Reflected XSS via Filter Parameter

Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results using an input field at the top. This field appends a filter parameter to the URL, which reflects its value directly into a `<script>` block without prop…

📅 Published: July 31, 2025, 1:48 p.m. 🔄 Last Modified: Sept. 22, 2025, 2:38 p.m.

7.2

CVSS3.1

CVE-2025-8213 - NinjaScanner – Virus & Malware scan <= 3.2.5 - Authenticated (Administrator+) Arbitrary File Deleti…

The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'nscan_ajax_quarantine' and 'nscan_quarantine_select' functions in all versions up to, and including, 3.2.5. This makes it possible for authenticated…

📅 Published: July 31, 2025, 12:24 p.m. 🔄 Last Modified: April 21, 2026, 4 a.m.

5.3

CVSS4.0

CVE-2025-8382 - Campcodes Online Hotel Reservation System edit_room.php sql injection

A vulnerability, which was classified as critical, was found in Campcodes Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/edit_room.php. The manipulation of the argument room_id leads to sql injection. It is possible to launch the attack remotely. The exploit…

📅 Published: July 31, 2025, 12:02 p.m. 🔄 Last Modified: Aug. 6, 2025, 4:40 p.m.
Total resulsts: 349182
Page 4447 of 34,919
« previous page » next page
Filters