6.9

CVSS4.0

CVE-2025-5625 - Campcodes Online Teacher Record Management System search-teacher.php sql injection

A vulnerability was found in Campcodes Online Teacher Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /search-teacher.php. The manipulation of the argument searchteacher leads to sql injection. The attack may be initiated remotely.…

πŸ“… Published: June 5, 2025, 12:31 a.m. πŸ”„ Last Modified: June 6, 2025, 3:16 p.m.

9.3

CVSS4.0

CVE-2025-5624 - D-Link DIR-816 QoSPortSetup stack-based overflow

A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the function QoSPortSetup of the file /goform/QoSPortSetup. The manipulation of the argument port0_group/port0_remarker/ssid0_group/ssid0_remarker leads to stack-based buffer overflow…

πŸ“… Published: June 5, 2025, 12:31 a.m. πŸ”„ Last Modified: June 6, 2025, 3:42 p.m.

9.4

CVSS4.0

CVE-2025-49008 - Atheos Improper Input Validation Vulnerability Enables RCE in Common.php

Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.php` allows argument injection, leading to arbitrary command execution. Atheos administrators and users of vulnerable ver…

πŸ“… Published: June 5, 2025, 12:13 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-5623 - D-Link DIR-816 qosClassifier stack-based overflow

A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been classified as critical. This affects the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to stack-based buffer overflow. It is possible to initiate the attack …

πŸ“… Published: June 5, 2025, midnight πŸ”„ Last Modified: June 6, 2025, 3:42 p.m.

9.3

CVSS4.0

CVE-2025-5622 - D-Link DIR-816 wirelessApcli_5g stack-based overflow

A vulnerability was found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this issue is the function wirelessApcli_5g of the file /goform/wirelessApcli_5g. The manipulation of the argument apcli_mode_5g/apcli_enc_5g/apcli_default_key_5g leads to stack-based buffer overflow. The …

πŸ“… Published: June 5, 2025, midnight πŸ”„ Last Modified: June 6, 2025, 3:42 p.m.

5.8

CVSS3.1

CVE-2025-49466 -

aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,

πŸ“… Published: June 5, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2025-47827 -

In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

πŸ“… Published: June 5, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

4

CVSS3.1

CVE-2025-48432 - django: Django Path Injection Vulnerability

An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead to log injection or forgery when logs are vie…

πŸ“… Published: June 5, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 5:47 p.m.

6.9

CVSS4.0

CVE-2025-5621 - D-Link DIR-816 qosClassifier os command injection

A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is the function qosClassifier of the file /goform/qosClassifier. The manipulation of the argument dip_address/sip_address leads to os command injection. The attack can be launched r…

πŸ“… Published: June 4, 2025, 11:31 p.m. πŸ”„ Last Modified: June 6, 2025, 3:42 p.m.

6.9

CVSS4.0

CVE-2025-5620 - D-Link DIR-816 setipsec_config os command injection

A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setipsec_config of the file /goform/setipsec_config. The manipulation of the argument localIP/remoteIP leads to os command injection. It is possible to launch the attack remotely. The …

πŸ“… Published: June 4, 2025, 11:31 p.m. πŸ”„ Last Modified: June 6, 2025, 3:42 p.m.
Total resulsts: 346692
Page 4921 of 34,670
Β« previous page Β» next page
Filters