9.8

CVSS3.1

CVE-2025-45865 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: May 15, 2025, 6:37 p.m.

9.8

CVSS3.1

CVE-2025-45858 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: May 23, 2025, 6:57 p.m.

5.1

CVSS3.1

CVE-2025-44039 -

CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive informat…

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: July 11, 2025, 2:11 p.m.

9.8

CVSS3.1

CVE-2025-28056 -

rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 6:07 p.m.

5.4

CVSS3.1

CVE-2025-45859 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: June 16, 2025, 6:25 p.m.

9.8

CVSS3.1

CVE-2025-44831 -

EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: June 16, 2025, 6:26 p.m.

7.2

CVSS3.1

CVE-2025-28057 -

owl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 2:09 a.m.

6.5

CVSS3.1

CVE-2025-45746 -

In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authenticate to the service console. NOTE: the Supplier disputes the significance of this report because the service console is typically only accessible from a local area network, and beca…

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2025-45861 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: May 15, 2025, 6:37 p.m.

7.5

CVSS3.1

CVE-2025-28055 -

upset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: July 9, 2025, 1:58 a.m.
Total resulsts: 346094
Page 5142 of 34,610
Β« previous page Β» next page
Filters