7.5

CVSS3.1

CVE-2025-44649 -

In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security paramete…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2025-44650 -

In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 5:58 p.m.

9.8

CVSS3.1

CVE-2025-44654 -

In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 9:03 p.m.

4.3

CVSS3.1

CVE-2025-43976 -

The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 6:12 p.m.

5.4

CVSS3.1

CVE-2025-51400 -

A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 1:24 a.m.

6.1

CVSS3.1

CVE-2024-55040 -

Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 6:14 p.m.

8.6

CVSS3.1

CVE-2025-36845 -

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only r…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Sept. 12, 2025, 6:09 p.m.

7.5

CVSS3.1

CVE-2025-51868 -

Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2025-46119 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfusca…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 5:18 p.m.

9.1

CVSS3.1

CVE-2025-52362 -

Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation for the _proxurl parameter can be bypassed, allowing a remote, unauthenticated attacker to submit a specially crafted URL

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4580 of 34,919
Β« previous page Β» next page
Filters