9.8

CVSS3.1

CVE-2025-54449 -

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

πŸ“… Published: July 23, 2025, 5:27 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

9.1

CVSS3.1

CVE-2025-54455 -

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.

πŸ“… Published: July 23, 2025, 5:27 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

9.1

CVSS3.1

CVE-2025-54454 -

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Server: less than 21.1080.0.

πŸ“… Published: July 23, 2025, 5:26 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

0.0

CVE-2025-8022 -

Bun Shell does not invoke /bin/sh, or any other interpreter, for template literals created with the $ function. Each ${…} interpolation is treated as a single argument. The security responsibility for this usage pattern lies with the calling application, which must ensure the sanitization and valid…

πŸ“… Published: July 23, 2025, 5 a.m. πŸ”„ Last Modified: Aug. 11, 2025, 10:15 a.m.

8.7

CVSS4.0

CVE-2025-8021 -

All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and access files outside of the intended directory.

πŸ“… Published: July 23, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-8020 -

All versions of the package private-ip are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide an IP or hostname that resolves to a multicast IP address (224.0.0.0/4) which is not included as part of the private IP ranges in the package's source code.

πŸ“… Published: July 23, 2025, 5 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-43881 -

Improper validation of specified quantity in input issue exists in Real-time Bus Tracking System versions prior to 1.1. If exploited, a denial of service (DoS) condition may be caused by an attacker who can log in to the administrative page of the affected product.

πŸ“… Published: July 23, 2025, 4:38 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-53288 -

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in NTP Region functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecified…

πŸ“… Published: July 23, 2025, 4:11 a.m. πŸ”„ Last Modified: July 29, 2025, 7:33 p.m.

5.9

CVSS3.1

CVE-2024-53287 -

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in VPN Setting functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to inject arbitrary web script or HTML via unspecifie…

πŸ“… Published: July 23, 2025, 4:11 a.m. πŸ”„ Last Modified: July 29, 2025, 7:33 p.m.

7.2

CVSS3.1

CVE-2024-53286 -

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in Synology Router Manager (SRM) before 1.3.1-9346-11 allows remote authenticated users with administrator privileges to execute arbitrary code via unspecified vecto…

πŸ“… Published: July 23, 2025, 4:11 a.m. πŸ”„ Last Modified: July 29, 2025, 7:34 p.m.
Total resulsts: 349182
Page 4542 of 34,919
Β« previous page Β» next page
Filters