8.7

CVSS4.0

CVE-2025-4810 - Tenda AC7 SetRebootTimer formSetRebootTimer stack-based overflow

A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. Affected by this vulnerability is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument reboot_time leads to stack-based buffer overflow. The attack can be launched r…

πŸ“… Published: May 16, 2025, 8:31 p.m. πŸ”„ Last Modified: May 24, 2025, 1:12 a.m.

4.8

CVSS4.0

CVE-2025-4805 - WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Acces Portal Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS. This vulnerability requires an authenticated administrator session to a locally managed Firebox. This issue affects Fireware OS: from 12.0 through 1…

πŸ“… Published: May 16, 2025, 8:13 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-4804 - WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Hotpot Configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox. This issue affects Firew…

πŸ“… Published: May 16, 2025, 8:12 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-4809 - Tenda AC7 setMacFilterCfg fromSafeSetMacFilter stack-based overflow

A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function fromSafeSetMacFilter of the file /goform/setMacFilterCfg. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to launch the attack remotely. …

πŸ“… Published: May 16, 2025, 8 p.m. πŸ”„ Last Modified: May 24, 2025, 1:11 a.m.

5.3

CVSS4.0

CVE-2025-4808 - PHPGurukul Park Ticketing Management System add-normal-ticket.php sql injection

A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0 and classified as critical. This issue affects some unknown processing of the file /add-normal-ticket.php. The manipulation of the argument noadult/nochildren/aprice/cprice leads to sql injection. The attack may be initiat…

πŸ“… Published: May 16, 2025, 8 p.m. πŸ”„ Last Modified: May 21, 2025, 8:59 p.m.

6.9

CVSS4.0

CVE-2025-4807 - SourceCodester Online Student Clearance System exposure of information through directory listing

A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. The manipulation leads to exposure of information through directory listing. It is possible to initiate the attack remotely. The exploit has been disc…

πŸ“… Published: May 16, 2025, 7:31 p.m. πŸ”„ Last Modified: May 28, 2025, 1:38 p.m.

3.1

CVSS3.1

CVE-2025-22233 - Spring Framework DataBinder Case Sensitive Match Exception

CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks. Affected Spring Products and Versions Spring Framework: *…

πŸ“… Published: May 16, 2025, 7:14 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-4806 - SourceCodester/oretnom23 Stock Management System view_bo sql injection

A vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=back_order/view_bo. The manipulation of the argument ID leads to sql injection. The attack may be …

πŸ“… Published: May 16, 2025, 7 p.m. πŸ”„ Last Modified: May 28, 2025, 1:46 p.m.

5.1

CVSS4.0

CVE-2025-4795 - gongfuxiang schoolcms index.php SaveInfo sql injection

A vulnerability classified as critical has been found in gongfuxiang schoolcms 2.3.1. This affects the function SaveInfo of the file /index.php?m=Admin&c=article&a=SaveInfo. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has b…

πŸ“… Published: May 16, 2025, 6:31 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 2:42 p.m.

6.9

CVSS4.0

CVE-2025-4794 - PHPGurukul Online Course Registration news.php sql injection

A vulnerability was found in PHPGurukul Online Course Registration 3.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /news.php. The manipulation of the argument newstitle leads to sql injection. The attack can be launched remotely. The exp…

πŸ“… Published: May 16, 2025, 6 p.m. πŸ”„ Last Modified: May 21, 2025, 9 p.m.
Total resulsts: 349182
Page 5361 of 34,919
Β« previous page Β» next page
Filters