7.2

CVSS3.1

CVE-2025-47948 - Cocotais Bot has builtin .echo command injection

Cocotais Bot is a QQ official robot framework based on qq-bot-sdk. Starting in version 1.5.0-test2-hotfix and prior to version 1.6.2, command echoing feature in the framework allows users to indirectly trigger privileged behavior by injecting special platform tags. Specifically, an unauthorized use…

πŸ“… Published: May 17, 2025, 6:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-47945 - Donetick Has Weak Default JWT Secret

Donetick an open-source app for managing tasks and chores. Prior to version 0.1.44, the application uses JSON Web Tokens (JWT) for authentication, but the signing secret has a weak default value. While the responsibility is left to the system administrator to change it, this approach is inadequate.…

πŸ“… Published: May 17, 2025, 6:36 p.m. πŸ”„ Last Modified: June 12, 2025, 4:28 p.m.

8.7

CVSS4.0

CVE-2025-4833 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formNtp buffer overflow

A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This issue affects some unknown processing of the file /boafrm/formNtp of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. T…

πŸ“… Published: May 17, 2025, 5:31 p.m. πŸ”„ Last Modified: May 23, 2025, 3:50 p.m.

8.7

CVSS4.0

CVE-2025-4832 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formDosCfg buffer overflow

A vulnerability has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formDosCfg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overfl…

πŸ“… Published: May 17, 2025, 5 p.m. πŸ”„ Last Modified: May 23, 2025, 3:51 p.m.

8.7

CVSS4.0

CVE-2025-4831 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSiteSurveyProfile buffer overflow

A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formSiteSurveyProfile of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer ove…

πŸ“… Published: May 17, 2025, 4:31 p.m. πŸ”„ Last Modified: May 23, 2025, 3:51 p.m.

8.5

CVSS3.1

CVE-2025-33103 - IBM i privilege escalation

IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 product IBM TCP/IP Connectivity Utilities for i contains a privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.

πŸ“… Published: May 17, 2025, 4:02 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

2.1

CVSS4.0

CVE-2025-47931 - LibreNMS stored Cross-site Scripting vulnerability in poller group name

LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerability in the `group name` parameter of the `http://localhost/poller/groups` form. This vulnerability allows attackers to inject malicious scripts into we…

πŸ“… Published: May 17, 2025, 3:51 p.m. πŸ”„ Last Modified: May 28, 2025, 1:19 p.m.

7.7

CVSS4.0

CVE-2025-47273 - setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File…

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with…

πŸ“… Published: May 17, 2025, 3:46 p.m. πŸ”„ Last Modified: June 12, 2025, 4:29 p.m.

8.7

CVSS4.0

CVE-2025-4830 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSysCmd buffer overflow

A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this issue is some unknown functionality of the file /boafrm/formSysCmd of the component HTTP POST Request Handler. The manipulation of the argument submit-url l…

πŸ“… Published: May 17, 2025, 3:31 p.m. πŸ”„ Last Modified: May 23, 2025, 3:51 p.m.

8.7

CVSS4.0

CVE-2025-4829 - TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formStats sub_40BE30 buffer overflow

A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this vulnerability is the function sub_40BE30 of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffe…

πŸ“… Published: May 17, 2025, 3 p.m. πŸ”„ Last Modified: May 23, 2025, 3:51 p.m.
Total resulsts: 349182
Page 5357 of 34,919
Β« previous page Β» next page
Filters