7.8

CVSS3.1

CVE-2024-49564 -

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system …

πŸ“… Published: March 28, 2025, 1:31 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.8

CVSS3.1

CVE-2024-49565 -

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privi…

πŸ“… Published: March 28, 2025, 1:28 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

9.1

CVSS3.1

CVE-2025-24383 -

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is …

πŸ“… Published: March 28, 2025, 1:24 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.7

CVSS3.1

CVE-2025-1860 - Data::Entropy for Perl uses insecure rand() function for cryptographic functions

Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is notΒ cryptographically secure,Β for cryptographic functions.

πŸ“… Published: March 28, 2025, 12:56 a.m. πŸ”„ Last Modified: Sept. 5, 2025, 2:15 p.m.

7.5

CVSS3.1

CVE-2025-28220 -

Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash via parameter funcpara1 passed to the binary through a POST request.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: May 6, 2025, 6:46 p.m.

9.8

CVSS3.1

CVE-2025-25579 -

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 2:23 p.m.

9.1

CVSS3.1

CVE-2025-28091 -

maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 2:17 p.m.

5.5

CVSS3.1

CVE-2025-28097 -

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 1:59 p.m.

9.8

CVSS3.1

CVE-2025-28256 -

An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 14, 2025, 5:06 p.m.

9.8

CVSS3.1

CVE-2024-38985 -

janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 4:39 p.m.
Total resulsts: 343975
Page 5636 of 34,398
Β« previous page Β» next page
Filters