8.8

CVSS3.1

CVE-2025-41683 - Weidmueller: Root Command Injection via Unsanitized Input in event_mail_test Endpoint

An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint event_mail_test).

πŸ“… Published: July 23, 2025, 8:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-8070 - Windows service registered with an unquoted ImagePath vulnerability in the system registry

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the service runs with elevated privileges, expl…

πŸ“… Published: July 23, 2025, 7:26 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-31701 -

A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such…

πŸ“… Published: July 23, 2025, 6:55 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-31700 -

A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such…

πŸ“… Published: July 23, 2025, 6:54 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-6174 - WordPress Qwizcards <= 3.9.4 - Reflected XSS

The Qwizcards | online quizzes and flashcards WordPress plugin through 3.9.4 does not sanitise and escape the "_stylesheet" parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or any other user.

πŸ“… Published: July 23, 2025, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-54439 -

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

πŸ“… Published: July 23, 2025, 5:36 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

9.8

CVSS3.1

CVE-2025-54438 -

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0

πŸ“… Published: July 23, 2025, 5:36 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

9.8

CVSS3.1

CVE-2025-54444 -

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

πŸ“… Published: July 23, 2025, 5:35 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

9.8

CVSS3.1

CVE-2025-54443 -

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0

πŸ“… Published: July 23, 2025, 5:34 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

9.8

CVSS3.1

CVE-2025-54442 -

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

πŸ“… Published: July 23, 2025, 5:34 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.
Total resulsts: 349182
Page 4540 of 34,919
Β« previous page Β» next page
Filters