9.4

CVSS4.0

CVE-2025-34049 - OptiLink ONT1GEW GPON Remote Code Execution

An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 1127.190306 and earlier. The router’s web management interface fails to properly sanitize user input in the target_addr parameter of the formTracert and formPing administrative endpo…

📅 Published: June 26, 2025, 3:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-34048 - D-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read

A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validation on the getpage parameter within the /cgi-bin/webproc CGI…

📅 Published: June 26, 2025, 3:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-34046 - Fanwei E-Office Unauthenticated File Upload

An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with certain parameters (uploadType=eoffice_logo or uploadType=th…

📅 Published: June 26, 2025, 3:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-34045 - WeiPHP Path Traversal Arbitrary File Read

A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework by Shenzhen Yuanmengyun Technology Co., Ltd. The flaw occurs in the picUrl parameter of the /public/index.php/material/Material/_download_imgage endpoint, where insufficient inpu…

📅 Published: June 26, 2025, 3:51 p.m. 🔄 Last Modified: Nov. 29, 2025, 3:25 p.m.

9.4

CVSS4.0

CVE-2025-34044 - WIFISKY 7-Layer Flow Control Router Remote Command Execution

A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence…

📅 Published: June 26, 2025, 3:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-34043 - Vacron NVR Remote Command Execution

A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.cgi script. The vulnerability allows unauthenticated attackers to pass arbitrary commands to the underlying operating system via crafted HTTP requests.…

📅 Published: June 26, 2025, 3:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-34042 - Beward N100 IP Camera Remote Command Execution

An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via the ServerName and TimeZone parameters in the servetest CGI page. An attacker with access to the web interface can inject arbitrary system commands into these parameters, which ar…

📅 Published: June 26, 2025, 3:51 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-6700 - Xuxueli xxl-sso login cross site scripting

A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of the file /xxl-sso-server/login. The manipulation of the argument errorMsg leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to t…

📅 Published: June 26, 2025, 3:31 p.m. 🔄 Last Modified: Sept. 15, 2025, 2:02 p.m.

5.1

CVSS4.0

CVE-2025-6699 - LabRedesCefetRJ WeGIA Cadastro de Funcionário cadastro_funcionario.php cross site scripting

A vulnerability classified as problematic has been found in LabRedesCefetRJ WeGIA 3.4.0. This affects an unknown part of the file /html/funcionario/cadastro_funcionario.php of the component Cadastro de Funcionário. The manipulation of the argument Nome/Sobrenome leads to cross site scripting. It is…

📅 Published: June 26, 2025, 3:31 p.m. 🔄 Last Modified: July 1, 2025, 3:42 p.m.

5.3

CVSS3.1

CVE-2025-36034 - IBM InfoSphere DataStage Flow Designer information disclosure

IBM InfoSphere DataStage Flow Designer in IBM InfoSphere Information Server 11.7 discloses sensitive user information in API requests in clear text that could be intercepted using man in the middle techniques.

📅 Published: June 26, 2025, 3:14 p.m. 🔄 Last Modified: Aug. 26, 2025, 2:51 p.m.
Total resulsts: 349182
Page 4877 of 34,919
« previous page » next page
Filters