7.5

CVSS3.1

CVE-2025-28220 -

Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash via parameter funcpara1 passed to the binary through a POST request.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 6:46 p.m.

9.8

CVSS3.1

CVE-2025-25579 -

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 7, 2025, 2:23 p.m.

9.1

CVSS3.1

CVE-2025-28091 -

maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 7, 2025, 2:17 p.m.

5.5

CVSS3.1

CVE-2025-28097 -

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 7, 2025, 1:59 p.m.

9.8

CVSS3.1

CVE-2025-28256 -

An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 14, 2025, 5:06 p.m.

9.8

CVSS3.1

CVE-2024-38985 -

janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 4:39 p.m.

7.5

CVSS3.1

CVE-2024-57083 - redoc: Prototype Pollution in redoc

A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 14, 2025, 5:02 p.m.

9.8

CVSS3.1

CVE-2024-38988 -

alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 14, 2025, 4:58 p.m.

5.4

CVSS3.1

CVE-2025-28096 -

OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 7, 2025, 2 p.m.

9.1

CVSS3.1

CVE-2025-28090 -

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

๐Ÿ“… Published: March 28, 2025, midnight ๐Ÿ”„ Last Modified: April 7, 2025, 2:18 p.m.
Total resulsts: 343981
Page 5637 of 34,399
ยซ previous page ยป next page
Filters