5.1

CVSS4.0

CVE-2025-53519 - Advantech iView Cross-site Scripting

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosur…

πŸ“… Published: July 10, 2025, 11:14 p.m. πŸ”„ Last Modified: July 23, 2025, 7:19 p.m.

5.1

CVSS4.0

CVE-2025-53397 - Advantech iView Cross-site Scripting

A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other m…

πŸ“… Published: July 10, 2025, 11:13 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 7:19 p.m.

8.7

CVSS4.0

CVE-2025-7419 - Tenda O3V2 httpd setRateTest fromSpeedTestSet stack-based overflow

A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fromSpeedTestSet of the file /goform/setRateTest of the component httpd. The manipulation of the argument destIP leads to stack-based buffer overflow. It is possible to initiate the…

πŸ“… Published: July 10, 2025, 11:02 p.m. πŸ”„ Last Modified: July 16, 2025, 4:40 p.m.

7.2

CVSS4.0

CVE-2025-1727 - End-of-Train and Head-of-Train Remote Linking Protocol Weak Authentication

The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH checksum for packet creation. It is possible to create these EoT and HoT packets with a software defined radio and issue brake control commands to the EoT device, disrupting op…

πŸ“… Published: July 10, 2025, 10:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-7418 - Tenda O3V2 httpd setPing fromPingResultGet stack-based overflow

A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the function fromPingResultGet of the file /goform/setPing of the component httpd. The manipulation of the argument destIP leads to stack-based buffer overflow. The attack may be launched re…

πŸ“… Published: July 10, 2025, 10:32 p.m. πŸ”„ Last Modified: July 16, 2025, 4:41 p.m.

4.6

CVSS3.1

CVE-2025-31267 - Authentication State Mismanagement Allows Physical Access to Sensitive User Information on AppΒ Stor…

An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.

πŸ“… Published: July 10, 2025, 10:23 p.m. πŸ”„ Last Modified: April 28, 2026, 1:15 a.m.

8.7

CVSS4.0

CVE-2025-7417 - Tenda O3V2 httpd setPingInfo fromNetToolGet stack-based overflow

A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability is the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be l…

πŸ“… Published: July 10, 2025, 10:02 p.m. πŸ”„ Last Modified: July 16, 2025, 4:41 p.m.

8.7

CVSS4.0

CVE-2025-7416 - Tenda O3V2 httpd setSysTimeInfo fromSysToolTime stack-based overflow

A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function fromSysToolTime of the file /goform/setSysTimeInfo of the component httpd. The manipulation of the argument Time leads to stack-based buffer overflow. It is possible to launch the att…

πŸ“… Published: July 10, 2025, 9:32 p.m. πŸ”„ Last Modified: July 16, 2025, 3 p.m.

4.1

CVSS3.1

CVE-2025-53637 - Meshtastic allows Command Injection in GitHub Action

Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be initiated by an attacker who forked the repository and created a pull request. In the shell code execution part, user-c…

πŸ“… Published: July 10, 2025, 9:31 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:02 p.m.

4.3

CVSS3.1

CVE-2025-24798 - Meshtastic crashes via an unimplemented routing module reply

Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. This can lead to a degradation of service for nodes within range of a malicious sender, or via MQTT if downlink is enabled. This vulne…

πŸ“… Published: July 10, 2025, 9:22 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 4:02 p.m.
Total resulsts: 349182
Page 4681 of 34,919
Β« previous page Β» next page
Filters