6.1

CVSS3.1

CVE-2025-3900 - Colorbox - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-041

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS).This issue affects Colorbox: from 0.0.0 before 2.1.3.

πŸ“… Published: April 23, 2025, 5:07 p.m. πŸ”„ Last Modified: June 20, 2025, 4:22 p.m.

7.2

CVSS3.0

CVE-2025-2773 - BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability

BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BEC Technologies Multiple Routers. Although authentication is required to exploit this vulnerability, t…

πŸ“… Published: April 23, 2025, 4:52 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:38 a.m.

6.5

CVSS3.1

CVE-2025-2772 - BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulne…

BEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is not required to exploit this v…

πŸ“… Published: April 23, 2025, 4:52 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:37 a.m.

5.3

CVSS3.0

CVE-2025-2771 - BEC Technologies Multiple Routers Authentication Bypass Vulnerability

BEC Technologies Multiple Routers Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of BEC Technologies routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-ba…

πŸ“… Published: April 23, 2025, 4:52 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 3:55 p.m.

6.5

CVSS3.1

CVE-2025-2770 - BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability

BEC Technologies Multiple Routers Cleartext Password Storage Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BEC Technologies routers. Authentication is required to exploit this vulnerability. The speci…

πŸ“… Published: April 23, 2025, 4:51 p.m. πŸ”„ Last Modified: Aug. 15, 2025, 7:18 p.m.

7.8

CVSS3.0

CVE-2025-2769 - Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in …

πŸ“… Published: April 23, 2025, 4:51 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 2:33 p.m.

7.8

CVSS3.0

CVE-2025-2768 - Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Bdrive NetDrive Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Bdrive NetDrive. An attacker must first obtain the ability to execute low-privileged code on the target system in …

πŸ“… Published: April 23, 2025, 4:51 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 2:39 p.m.

9.6

CVSS3.1

CVE-2025-2767 - Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability

Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists…

πŸ“… Published: April 23, 2025, 4:51 p.m. πŸ”„ Last Modified: Aug. 14, 2025, 2:40 p.m.

8.8

CVSS3.1

CVE-2025-2765 - CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability

CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of CarlinKit CPC200-CCPA devices. Authentication is not required to exploit this vulnerability. …

πŸ“… Published: April 23, 2025, 4:48 p.m. πŸ”„ Last Modified: July 11, 2025, 2:01 p.m.

8

CVSS3.0

CVE-2025-2764 - CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vu…

CarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of CarlinKit CPC200-CCPA devices. Although authentication is required to exploit t…

πŸ“… Published: April 23, 2025, 4:48 p.m. πŸ”„ Last Modified: July 11, 2025, 2:01 p.m.
Total resulsts: 346661
Page 5434 of 34,667
Β« previous page Β» next page
Filters