6.5

CVSS3.1

CVE-2025-28371 -

EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password.

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:26 p.m.

6.5

CVSS3.1

CVE-2025-43714 -

The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers.

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:24 p.m.

7.6

CVSS3.1

CVE-2025-30072 -

Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:25 p.m.

4.8

CVSS3.1

CVE-2025-44108 -

A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.

πŸ“… Published: May 19, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:26 p.m.

5.3

CVSS4.0

CVE-2025-4901 - D-Link DI-7003GV2 HTTP Endpoint state_view.data sub_41E304 information disclosure

A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information disclosure. The attack can only be done withi…

πŸ“… Published: May 18, 2025, 11:31 p.m. πŸ”„ Last Modified: May 21, 2025, 1:40 p.m.

6.9

CVSS4.0

CVE-2025-4900 - Campcodes Sales and Inventory System payment.php sql injection

A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/payment.php. The manipulation of the argument cid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclose…

πŸ“… Published: May 18, 2025, 11 p.m. πŸ”„ Last Modified: May 21, 2025, 7:37 p.m.

6.9

CVSS4.0

CVE-2025-4899 - Campcodes Sales and Inventory System transaction_update.php sql injection

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pages/transaction_update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit h…

πŸ“… Published: May 18, 2025, 10:31 p.m. πŸ”„ Last Modified: May 21, 2025, 7:37 p.m.

5.3

CVSS4.0

CVE-2025-4898 - SourceCodester Student Result Management System Logo File update_system.php unlink path traversal

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects the function unlink of the file update_system.php of the component Logo File Handler. The manipulation of the argument old_logo leads to path traversal. The…

πŸ“… Published: May 18, 2025, 10 p.m. πŸ”„ Last Modified: May 21, 2025, 7:37 p.m.

8.7

CVSS4.0

CVE-2025-4897 - Tenda A15 HTTP POST Request multimodalAdd buffer overflow

A vulnerability was found in Tenda A15 15.13.07.09/15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/multimodalAdd of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. T…

πŸ“… Published: May 18, 2025, 9:31 p.m. πŸ”„ Last Modified: May 27, 2025, 4:30 p.m.

8.7

CVSS4.0

CVE-2025-4896 - Tenda AC10 UserCongratulationsExec buffer overflow

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/UserCongratulationsExec. The manipulation of the argument getuid leads to buffer overflow. The attack may be launched remotely. The exploit has be…

πŸ“… Published: May 18, 2025, 9 p.m. πŸ”„ Last Modified: May 27, 2025, 4:30 p.m.
Total resulsts: 349182
Page 5350 of 34,919
Β« previous page Β» next page
Filters