8.6

CVSS4.0

CVE-2025-25427 - XSS in TP-Link TL-WR841N v14/v14.6/v14.8 Upnp page

A stored cross-site scripting (XSS) vulnerability in the upnp.htm page of the web Interface in TP-Link WR841N v14/v14.6/v14.8 <= Build 241230 Rel. 50788n allows remote attackers to inject arbitrary JavaScript code via the port mapping description. This leads to an execution of the JavaScript payloaโ€ฆ

๐Ÿ“… Published: April 18, 2025, 12:03 a.m. ๐Ÿ”„ Last Modified: July 9, 2025, 5:35 p.m.

9.8

CVSS3.1

CVE-2025-28242 -

Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-28235 -

An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 and Ui16 Firmware v1.0.7x and v1.0.5x allows attackers to access Administrator credentials in plaintext.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-40364 - io_uring: fix io_req_prep_async with provided buffers

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_req_prep_async with provided buffers io_req_prep_async() can import provided buffers, commit the ring state by giving up on that before, it'll be reimported later if needed.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 17, 2025, 2:06 p.m.

9.1

CVSS3.1

CVE-2024-29643 -

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: May 28, 2025, 3:51 p.m.

5.5

CVSS3.1

CVE-2025-38575 - ksmbd: use aead_request_free to match aead_request_alloc

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free() instead of kfree() to properly free memory allocated by aead_request_alloc(). This ensures sensitive crypto data is zeroed before being freed.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: March 17, 2026, 2:31 p.m.

9.8

CVSS3.1

CVE-2024-53591 -

An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: June 23, 2025, 7:41 p.m.

6.3

CVSS3.1

CVE-2024-46089 -

74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: May 28, 2025, 5:39 p.m.

9.1

CVSS3.1

CVE-2025-28233 -

Incorrect access control in BW Broadcast TX600 (14980), TX300 (32990) (31448), TX150, TX1000, TX30, and TX50 Hardware Version: 2, Software Version: 1.6.0, Control Version: 1.0, AIO Firmware Version: 1.7 allows attackers to access log files and extract session identifiers to execute a session hijackโ€ฆ

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-28228 -

A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.

๐Ÿ“… Published: April 18, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 7, 2025, 2:08 p.m.
Total resulsts: 346449
Page 5449 of 34,645
ยซ previous page ยป next page
Filters