6.7

CVSS3.1

CVE-2025-29983 -

Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸ“… Published: April 15, 2025, 3:30 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

5.1

CVSS4.0

CVE-2025-3613 - Demtec Graphytics visualization cross site scripting

A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unknown code of the file /visualization. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclos…

πŸ“… Published: April 15, 2025, 3 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-3612 - Demtec Graphytics HTTP GET Parameter visualization cross site scripting

A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part of the file /visualization of the component HTTP GET Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploi…

πŸ“… Published: April 15, 2025, 3 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-3470 - TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.6 - Authenticated (Administrator+) SQL…

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th…

πŸ“… Published: April 15, 2025, 1:44 a.m. πŸ”„ Last Modified: April 22, 2026, 5:45 p.m.

7.3

CVSS3.1

CVE-2024-36842 -

An issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build Number PlatformVER:K24-2023/05/09-v0.01 allows a remote attacker to execute arbitrary code via the ADB port component.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-3576 - Krb5: kerberos rc4-hmac-md5 checksum vulnerability enabling message spoofing via md5 collisions

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may …

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-22900 -

Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig function.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 4:55 p.m.

5.6

CVSS3.1

CVE-2025-22911 -

RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 4:28 p.m.

5

CVSS3.1

CVE-2025-32102 -

CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request to the /WebInterface/function/ URI.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

4

CVSS3.1

CVE-2025-32996 - http-proxy-middleware: Always-Incorrect Control Flow Implementation in http-proxy-middleware

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.

πŸ“… Published: April 15, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 2:43 p.m.
Total resulsts: 346551
Page 5621 of 34,656
Β« previous page Β» next page
Filters