9.3

CVSS4.0

CVE-2025-5600 - TOTOLINK EX1200T cstecgi.cgi setLanguageCfg stack-based overflow

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument LangType leads to stack-based buffer overflow. The attack may be initiated โ€ฆ

๐Ÿ“… Published: June 4, 2025, 5:31 p.m. ๐Ÿ”„ Last Modified: June 10, 2025, 3:09 p.m.

6.9

CVSS4.0

CVE-2025-5599 - PHPGurukul Student Result Management System editmyexp.php sql injection

A vulnerability classified as critical was found in PHPGurukul Student Result Management System 1.3. This vulnerability affects unknown code of the file /editmyexp.php. The manipulation of the argument emp1ctc leads to sql injection. The attack can be initiated remotely. The exploit has been discloโ€ฆ

๐Ÿ“… Published: June 4, 2025, 5:31 p.m. ๐Ÿ”„ Last Modified: June 9, 2025, 3 p.m.

7.5

CVSS4.0

CVE-2025-5688 - Out of Bounds Write in FreeRTOS-Plus-TCP

We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only affects systems using Buffer Allocation Scheme 1 with LLMNR or mDNS enabled. Users should upgrade to the latest version and ensure any forked or โ€ฆ

๐Ÿ“… Published: June 4, 2025, 5:09 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-5596 - FreeFloat FTP Server REGET Command buffer overflow

A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component REGET Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public anโ€ฆ

๐Ÿ“… Published: June 4, 2025, 5 p.m. ๐Ÿ”„ Last Modified: June 24, 2025, 3:21 p.m.

4.8

CVSS3.1

CVE-2025-2336 - AngularJS improper sanitization in SVG '<image>' element with 'ngSanitize'

Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '<image>' SVG elements in AngularJS'sย 'ngSanitize'ย module allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofinโ€ฆ

๐Ÿ“… Published: June 4, 2025, 4:32 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-5595 - FreeFloat FTP Server PROGRESS Command buffer overflow

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown processing of the component PROGRESS Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and mโ€ฆ

๐Ÿ“… Published: June 4, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: June 24, 2025, 3:21 p.m.

5.3

CVSS3.1

CVE-2025-20259 - Cisco ThousandEyes Endpoint Agent for Windows Arbitrary File Write Vulnerability

Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device. These vulnerabilities are due to improper access controls on files that are in the local file system. An aโ€ฆ

๐Ÿ“… Published: June 4, 2025, 4:22 p.m. ๐Ÿ”„ Last Modified: July 22, 2025, 3:31 p.m.

9.9

CVSS3.1

CVE-2025-20286 - ISE on AWS Static Credential

A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configuraโ€ฆ

๐Ÿ“… Published: June 4, 2025, 4:18 p.m. ๐Ÿ”„ Last Modified: Oct. 15, 2025, 5:58 p.m.

6

CVSS3.1

CVE-2025-20278 - Cisco Unified Communications Products Command Injection Vulnerability

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied comโ€ฆ

๐Ÿ“… Published: June 4, 2025, 4:18 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 5:51 p.m.

4.8

CVSS3.1

CVE-2025-20279 - Cisco Unifed Contact Center Express Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to conduct a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to imprโ€ฆ

๐Ÿ“… Published: June 4, 2025, 4:18 p.m. ๐Ÿ”„ Last Modified: July 22, 2025, 1:41 p.m.
Total resulsts: 348200
Page 5076 of 34,820
ยซ previous page ยป next page
Filters