10

CVSS3.1

CVE-2024-46506 -

NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as exploited in the wild in May 2025. This is related to settings.php and util.php.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 7:39 p.m.

5.4

CVSS3.1

CVE-2025-45864 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 7:41 p.m.

8.6

CVSS3.1

CVE-2024-48766 -

NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal, as exploited in the wild in May 2025. This is related to components/logs.php.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: June 24, 2025, 8:04 p.m.

5.4

CVSS3.1

CVE-2025-45867 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 7:39 p.m.

5.4

CVSS3.1

CVE-2025-47905 - varnish: request smuggling attacks

Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-45857 -

EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: July 11, 2025, 2:42 p.m.

9.8

CVSS3.1

CVE-2025-45863 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: May 23, 2025, 6:55 p.m.

5.4

CVSS3.1

CVE-2025-45866 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 7:39 p.m.

9.8

CVSS3.1

CVE-2025-45865 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: May 15, 2025, 6:37 p.m.

5.1

CVSS3.1

CVE-2025-44039 -

CP-XR-DE21-S -4G Router Firmware version 1.031.022 was discovered to contain insecure protections for its UART console. This vulnerability allows local attackers to connect to the UART port via a serial connection, read all boot sequence, and revealing internal system details and sensitive informat…

πŸ“… Published: May 13, 2025, midnight πŸ”„ Last Modified: July 11, 2025, 2:11 p.m.
Total resulsts: 349182
Page 5450 of 34,919
Β« previous page Β» next page
Filters