7.8

CVSS3.1

CVE-2025-36564 -

Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.

📅 Published: June 3, 2025, 2:41 p.m. 🔄 Last Modified: Feb. 26, 2026, 6:27 p.m.

5.3

CVSS4.0

CVE-2025-5504 - TOTOLINK X2000R formWsc command injection

A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWsc. The manipulation of the argument peerRptPin leads to command injection. The attack can be initiated remotely. The exploit has been …

📅 Published: June 3, 2025, 2:31 p.m. 🔄 Last Modified: June 17, 2025, 8:40 p.m.

8.7

CVSS4.0

CVE-2025-5503 - TOTOLINK X15 formMapReboot stack-based overflow

A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the function formMapReboot of the file /boafrm/formMapReboot. The manipulation of the argument deviceMacAddr leads to stack-based buffer overflow. It is possible to initiate the attack re…

📅 Published: June 3, 2025, 2:31 p.m. 🔄 Last Modified: June 17, 2025, 8:40 p.m.

5.3

CVSS4.0

CVE-2025-5502 - TOTOLINK X15 formMapReboot command injection

A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this issue is the function formMapReboot of the file /boafrm/formMapReboot. The manipulation of the argument deviceMacAddr leads to command injection. The attack may be launched remot…

📅 Published: June 3, 2025, 2 p.m. 🔄 Last Modified: June 6, 2025, 5:42 p.m.

6.9

CVSS4.0

CVE-2025-5501 - Open5GS NGAP PathSwitchRequest Message ngap-handler.c ngap_handle_path_switch_request_transfer asse…

A vulnerability classified as problematic was found in Open5GS up to 2.7.3. Affected by this vulnerability is the function ngap_handle_path_switch_request_transfer of the file src/smf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to reachable asserti…

📅 Published: June 3, 2025, 2 p.m. 🔄 Last Modified: June 13, 2025, 7:36 p.m.

6.9

CVSS4.0

CVE-2025-5499 - slackero phpwcms image_resized.php getimagesize deserialization

A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function is_file/getimagesize of the file image_resized.php. The manipulation of the argument imgfile leads to deserialization. It is possible to launch the attack remotely. The exploit ha…

📅 Published: June 3, 2025, 1:31 p.m. 🔄 Last Modified: Jan. 20, 2026, 3:46 p.m.

5.1

CVSS4.0

CVE-2025-5498 - slackero phpwcms Custom Source Tab cnt21.readform.inc.php is_file deserialization

A vulnerability was found in slackero phpwcms up to 1.9.45/1.10.8. It has been rated as critical. This issue affects the function file_get_contents/is_file of the file include/inc_lib/content/cnt21.readform.inc.php of the component Custom Source Tab. The manipulation of the argument cpage_custom le…

📅 Published: June 3, 2025, 1:31 p.m. 🔄 Last Modified: Jan. 20, 2026, 3:38 p.m.

5.3

CVSS4.0

CVE-2025-5497 - slackero phpwcms Feedimport processing.inc.php deserialization

A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the file include/inc_module/mod_feedimport/inc/processing.inc.php of the component Feedimport Module. Performing manipulation of the argument cnt_text results in deserialization. The…

📅 Published: June 3, 2025, 1 p.m. 🔄 Last Modified: Aug. 20, 2025, 9:15 a.m.

5.3

CVSS3.1

CVE-2024-12718 - Bypass extraction filter to modify file metadata outside extraction directory

Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or Tar…

📅 Published: June 3, 2025, 12:59 p.m. 🔄 Last Modified: April 21, 2026, 8:11 p.m.

7.5

CVSS3.1

CVE-2025-4435 - Tarfile extracts filtered members when errorlevel=0

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the member would still be extracted and not skipped.

📅 Published: June 3, 2025, 12:59 p.m. 🔄 Last Modified: April 21, 2026, 8:16 p.m.
Total resulsts: 346617
Page 4932 of 34,662
« previous page » next page
Filters