9.3

CVSS4.0

CVE-2025-34132 - LILIN DVR Command Injection via NTPUpdate in dvr_box

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute โ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-34130 - LILIN DVR Arbitrary File Read via net_html.cgi

An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin/net_html.cgi endpoint. This vulnerability allows attackers to read sensitive configuration files, such as /zconf/service.xml, which can then be used โ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-34129 - LILIN DVR RCE via Malicious FTP/NTP Configuration

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the configuration interface can upload a maliciโ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:26 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-34128 - X360 VideoPlayer ActiveX Control Buffer Overflow via ConvertFile()

A buffer overflow vulnerability exists in the X360 VideoPlayer ActiveX control (VideoPlayer.ocx) version 2.6 when handling overly long arguments to the ConvertFile() method. An attacker can exploit this vulnerability by supplying crafted input to cause memory corruption and execute arbitrary code wโ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:10 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 10:30 p.m.

9.3

CVSS4.0

CVE-2025-34127 - Achat v0.150 SEH Buffer Overflow via UDP

A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds checking on user-supplied input leading to remote code executioโ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:10 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 10:30 p.m.

8.7

CVSS4.0

CVE-2025-34126 - RIPS Scanner v0.54 Path Traversal

A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read arbitrary files on the system with the privileges of the web server by sending crafted HTTP GET requests to the 'windows/code.php' script with a manipulated 'file' parameter. This cโ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:10 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-34125 - D-Link DSP-W110A1 Cookie Command Injection

An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlyinโ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:09 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 10:30 p.m.

8.4

CVSS4.0

CVE-2025-34124 - Heroes of Might and Magic III .h3m Map File Buffer Overflow

A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a bufferโ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:08 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2025-34123 - VideoCharge Studio 2.12.3.685 SEH Buffer Overflow via .VSC File

A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The issue occurs due to improper handling of user-supplied data in the XML 'Name' attribute, leading to an SEH overwrite condition. An attacker can exploiโ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:07 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 10:30 p.m.

9.3

CVSS4.0

CVE-2025-34121 - Idera Up.Time โ‰ค 7.2 post2file.php Arbitrary File Upload RCE

An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results inโ€ฆ

๐Ÿ“… Published: July 16, 2025, 9:06 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 10:30 p.m.
Total resulsts: 349182
Page 4612 of 34,919
ยซ previous page ยป next page
Filters