6.9

CVSS4.0

CVE-2025-4301 - itsourcecode Content Management System search-notice.php sql injection

A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search-notice.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exp…

πŸ“… Published: May 6, 2025, 12:31 a.m. πŸ”„ Last Modified: May 13, 2025, 8:21 p.m.

6.9

CVSS4.0

CVE-2025-4300 - itsourcecode Content Management System search_list.php sql injection

A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unknown function of the file /search_list.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been discl…

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:22 p.m.

8.7

CVSS4.0

CVE-2025-4299 - Tenda AC1206 openSchedWifi setSchedWifi buffer overflow

A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public a…

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:06 p.m.

6.5

CVSS3.1

CVE-2025-4374 - Quay: incorrect privilege assignment

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: Feb. 27, 2026, 4:40 p.m.

6.5

CVSS3.1

CVE-2025-45490 -

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:19 p.m.

5.6

CVSS3.1

CVE-2025-47256 -

Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 2:13 p.m.

6.5

CVSS3.1

CVE-2025-45492 -

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:19 p.m.

9.8

CVSS3.1

CVE-2025-45491 -

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:19 p.m.

6.5

CVSS3.1

CVE-2025-45489 -

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the hostname parameter.

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:19 p.m.

6.5

CVSS3.1

CVE-2025-45488 -

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.

πŸ“… Published: May 6, 2025, midnight πŸ”„ Last Modified: May 13, 2025, 8:19 p.m.
Total resulsts: 343825
Page 5009 of 34,383
Β« previous page Β» next page
Filters