3.7

CVSS3.1

CVE-2025-49011 - SpiceDB checks involving relations with caveats can result in no permission when permission is expe…

SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple caveated branches, requests…

πŸ“… Published: June 6, 2025, 5:36 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 4:48 p.m.

7.5

CVSS3.1

CVE-2025-47950 - CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification

CoreDNS is a DNS server that chains plugins. In versions prior to 1.12.2, a Denial of Service (DoS) vulnerability exists in the CoreDNS DNS-over-QUIC (DoQ) server implementation. The server previously created a new goroutine for every incoming QUIC stream without imposing any limits on the number o…

πŸ“… Published: June 6, 2025, 5:32 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 4:24 p.m.

8.7

CVSS4.0

CVE-2025-5790 - TOTOLINK X15 HTTP POST Request formIpQoS buffer overflow

A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. This vulnerability affects unknown code of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can be initiated remotel…

πŸ“… Published: June 6, 2025, 5:31 p.m. πŸ”„ Last Modified: June 17, 2025, 9:30 p.m.

8.7

CVSS4.0

CVE-2025-5789 - TOTOLINK X15 HTTP POST Request formPortFw buffer overflow

A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type leads to buffer overflow. It is possible to initiate the …

πŸ“… Published: June 6, 2025, 5:31 p.m. πŸ”„ Last Modified: June 9, 2025, 7:08 p.m.

8.7

CVSS4.0

CVE-2025-5788 - TOTOLINK X15 HTTP POST Request formReflashClientTbl buffer overflow

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overfl…

πŸ“… Published: June 6, 2025, 5 p.m. πŸ”„ Last Modified: June 9, 2025, 7:08 p.m.

8.7

CVSS4.0

CVE-2025-5787 - TOTOLINK X15 HTTP POST Request formWsc buffer overflow

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. …

πŸ“… Published: June 6, 2025, 4:31 p.m. πŸ”„ Last Modified: June 9, 2025, 7:08 p.m.

8.7

CVSS4.0

CVE-2025-5786 - TOTOLINK X15 HTTP POST Request formDMZ buffer overflow

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch …

πŸ“… Published: June 6, 2025, 4:31 p.m. πŸ”„ Last Modified: June 10, 2025, 2:56 p.m.

8.7

CVSS4.0

CVE-2025-5785 - TOTOLINK X15 HTTP POST Request formWirelessTbl buffer overflow

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may …

πŸ“… Published: June 6, 2025, 4 p.m. πŸ”„ Last Modified: June 10, 2025, 2:56 p.m.

5.3

CVSS4.0

CVE-2025-5784 - PHPGurukul Employee Record Management System myexp.php sql injection

A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vulnerability affects unknown code of the file /myexp.php. The manipulation of the argument emp3ctc leads to sql injection. The attack can be initiated remotely. The exploit has been …

πŸ“… Published: June 6, 2025, 4 p.m. πŸ”„ Last Modified: June 10, 2025, 2:56 p.m.

8.3

CVSS4.0

CVE-2025-29885 - File Station 5

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerability could allow remote attackers who have gained user access to compromise the security of the system. We have already fixed the vulnerability in the following versions: File St…

πŸ“… Published: June 6, 2025, 3:54 p.m. πŸ”„ Last Modified: June 18, 2025, 7:24 p.m.
Total resulsts: 349182
Page 5129 of 34,919
Β« previous page Β» next page
Filters