6.5

CVSS3.1

CVE-2025-32993 -

Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 6:39 p.m.

6.5

CVSS3.1

CVE-2025-28144 -

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin parameter in the formWsc function.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 6:43 p.m.

6.1

CVSS3.1

CVE-2025-33028 -

In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete fix for CVE-2024-8811. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of WinZip. User interaction is required to exploit this vulnerabil…

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: Oct. 24, 2025, 8:16 p.m.

6.1

CVSS3.1

CVE-2025-33027 -

In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Bandizip. User interaction is required to exploit this vulnerability in that the target must visit…

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: Oct. 24, 2025, 8:16 p.m.

6.1

CVSS3.1

CVE-2025-33026 -

In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of PeaZip. User interaction is required to exploit this vulnerability in that the target must visit a malicious…

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: Oct. 24, 2025, 8:15 p.m.

9.8

CVSS3.1

CVE-2025-28100 -

A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:54 p.m.

6.5

CVSS3.1

CVE-2025-24949 -

In JotUrl 2.0, is possible to bypass security requirements during the password change process.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 5:07 p.m.

9.8

CVSS3.1

CVE-2025-25456 -

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:43 p.m.

6.5

CVSS3.1

CVE-2025-28143 -

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: May 1, 2025, 2:26 p.m.

9.8

CVSS3.1

CVE-2025-28399 -

An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 25, 2025, 4:53 p.m.
Total resulsts: 342375
Page 5206 of 34,238
Β« previous page Β» next page
Filters