9.8

CVSS3.1

CVE-2025-25456 -

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 4:43 p.m.

6.5

CVSS3.1

CVE-2025-28143 -

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: May 1, 2025, 2:26 p.m.

9.8

CVSS3.1

CVE-2025-28399 -

An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 25, 2025, 4:53 p.m.

6.5

CVSS3.1

CVE-2025-27980 -

cashbook v4.0.3 has an arbitrary file read vulnerability in /api/entry/flow/invoice/show?invoice=.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: May 22, 2025, 3:53 p.m.

5.9

CVSS3.1

CVE-2024-44843 -

An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 25, 2025, 4:48 p.m.

6.5

CVSS3.1

CVE-2025-32993 -

Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-29705 -

code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 5:46 p.m.

8.8

CVSS3.1

CVE-2025-29281 -

In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 3:17 p.m.

5.9

CVSS3.1

CVE-2025-28198 -

A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the orderBy parameter of the StoreController.java component.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 6:24 p.m.

6.5

CVSS3.1

CVE-2025-24948 -

In JotUrl 2.0, passwords are sent via HTTP GET-type requests, potentially exposing credentials to eavesdropping or insecure records.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 6:41 p.m.
Total resulsts: 346560
Page 5625 of 34,656
ยซ previous page ยป next page
Filters