8.6
CVE-2025-25427 - XSS in TP-Link TL-WR841N v14/v14.6/v14.8 Upnp page
A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 Rel. 50788n allows remote attackers to inject arbitrary JavaScript code via the port mapping description. This leads to an execution of the JavaScript payloaโฆ
9.8
CVE-2025-28242 -
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.
7.5
CVE-2025-28235 -
An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext.
7.8
CVE-2025-40364 - io_uring: fix io_req_prep_async with provided buffers
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.
9.1
CVE-2024-29643 -
An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
5.5
CVE-2025-38575 - ksmbd: use aead_request_free to match aead_request_alloc
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free() instead of kfree() to properly free memory allocated by aead_request_alloc(). This ensures sensitive crypto data is zeroed before being freed.
9.8
CVE-2024-53591 -
An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.
6.3
CVE-2024-46089 -
74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
9.1
CVE-2025-28233 -
Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract session identifiers to execute a session hijackโฆ
7.5
CVE-2025-28228 -
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.