7.5

CVSS3.1

CVE-2025-1021 -

Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors.

๐Ÿ“… Published: April 23, 2025, 2:49 a.m. ๐Ÿ”„ Last Modified: Nov. 17, 2025, 2:10 p.m.

7.3

CVSS3.1

CVE-2025-28018 -

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 8:35 p.m.

8.1

CVSS3.1

CVE-2025-28169 -

BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the manufacturer's cloud server unencrypted, allowing attackers to execute a man-in-the-middle attack.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

9.8

CVSS3.1

CVE-2025-45429 -

In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 3:48 p.m.

6.1

CVSS3.1

CVE-2025-29526 -

A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.

7.3

CVSS3.1

CVE-2025-28019 -

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 8:35 p.m.

6.5

CVSS3.1

CVE-2025-28017 -

TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 8:35 p.m.

2.5

CVSS3.1

CVE-2024-58251 -

In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: July 12, 2025, 10:16 p.m.

9.8

CVSS3.1

CVE-2025-45428 -

In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 4:12 p.m.

5.8

CVSS3.1

CVE-2025-43716 -

A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the URI of the /client/index.php endpoint, an attacker can bypass access controls and gain unauthorized access to various endpoints such as /client/index.php%3F.php/gsb/firewall.โ€ฆ

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: April 29, 2025, 1:52 p.m.
Total resulsts: 343968
Page 5170 of 34,397
ยซ previous page ยป next page
Filters