6.7

CVSS3.1

CVE-2025-1732 -

An improper privilege management vulnerability in the recovery function of the Zyxel USG FLEX H series uOS firmware version V1.31 and earlier could allow an authenticated local attacker with administrator privileges to upload a crafted configuration file and escalate privileges on a vulnerable devi…

πŸ“… Published: April 22, 2025, 1:57 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

7.8

CVSS3.1

CVE-2025-1731 -

An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 through V1.31 could allow an authenticated local attacker with low privileges to gain access to the Linux shell and escalate their privileges by crafting malic…

πŸ“… Published: April 22, 2025, 1:52 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

5.3

CVSS4.0

CVE-2025-3856 - xxyopen Novel-Plus searchByPage sql injection

A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function searchByPage of the file /book/searchByPage. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclo…

πŸ“… Published: April 22, 2025, 1 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 6:49 p.m.

5.3

CVSS4.0

CVE-2025-3855 - CodeCanyon RISE Ultimate Project Manager Profile Picture save_profile_image resource injection

A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php/team_members/save_profile_image/ of the component Profile Picture Handler. The manipulation of the argument profile_…

πŸ“… Published: April 22, 2025, 12:31 a.m. πŸ”„ Last Modified: Aug. 1, 2025, 10:06 p.m.

8.6

CVSS4.0

CVE-2025-3854 - H3C GR-3000AX HTTP POST Request aspForm Edit_List_SSID buffer overflow

A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function EnableIpv6/UpdateWanModeMulti/UpdateIpv6Params/EditWlanMacList/Edit_List_SSID of the file /goform/aspForm of the component HTTP POST Request Handler. The manipulation of the argume…

πŸ“… Published: April 22, 2025, 12:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-3850 - YXJ2018 SpringBoot-Vue-OnlineExam API improper authentication

A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The manipulation leads to improper authentication. The attack may be initiated remotely. The complexity of an attack is rat…

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: Oct. 15, 2025, 6:52 p.m.

7.7

CVSS3.1

CVE-2024-33452 - lua-nginx-module: HTTP request smuggling via a crafted HEAD request

An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

7.3

CVSS3.1

CVE-2025-28032 -

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm par…

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 4:19 p.m.

7.3

CVSS3.1

CVE-2024-46546 -

NEXTU FLETA AX1500 WIFI6 Router v1.0.3 was discovered to contain a stack overflow via the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 6:28 p.m.

7.5

CVSS3.1

CVE-2025-29339 -

An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid value propagated from SMF (or via direct attack), triggerin…

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: June 19, 2025, 12:23 a.m.
Total resulsts: 346528
Page 5436 of 34,653
Β« previous page Β» next page
Filters