4.9

CVSS3.1

CVE-2025-3470 - TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.6 - Authenticated (Administrator+) SQL…

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th…

πŸ“… Published: April 15, 2025, 1:44 a.m. πŸ”„ Last Modified: April 15, 2025, 6:39 p.m.

7.3

CVSS3.1

CVE-2024-36842 -

An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build Number PlatformVER:K24-2023/05/09-v0.01 allows a remote attacker to execute arbitrary code via the ADB port component.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 8:15 p.m.

9.8

CVSS3.1

CVE-2025-22900 -

Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:55 p.m.

5.6

CVSS3.1

CVE-2025-22911 -

RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 4:28 p.m.

5

CVSS3.1

CVE-2025-32102 -

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

4

CVSS3.1

CVE-2025-32996 - http-proxy-middleware: Always-Incorrect Control Flow Implementation in http-proxy-middleware

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 2:43 p.m.

4.6

CVSS3.1

CVE-2025-22903 -

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:55 p.m.

4.6

CVSS3.1

CVE-2025-25458 -

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:43 p.m.

6.5

CVSS3.1

CVE-2025-28142 -

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: May 1, 2025, 2:26 p.m.

6.8

CVSS3.1

CVE-2025-27892 -

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 4:30 p.m.
Total resulsts: 342387
Page 5205 of 34,239
Β« previous page Β» next page
Filters