9.8

CVSS3.1

CVE-2025-26003 -

Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 4:34 p.m.

5.3

CVSS3.1

CVE-2025-30742 -

httpd.c in atophttpd 2.8.0 has an off-by-one error and resultant out-of-bounds read because a certain 1024-character req string would not have a final '\0' character.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

7.5

CVSS3.1

CVE-2025-28361 -

Unauthorized stack overflow vulnerability in Telesquare TLR-2005KSH v.1.1.4 allows a remote attacker to obtain sensitive information via the systemutil.cgi component.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 3:43 p.m.

6.8

CVSS3.1

CVE-2024-41643 -

An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.

9.8

CVSS3.1

CVE-2025-26005 -

Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 4:34 p.m.

9.8

CVSS3.1

CVE-2025-26007 -

Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.

πŸ“… Published: March 26, 2025, midnight πŸ”„ Last Modified: April 1, 2025, 4:34 p.m.

4.3

CVSS3.1

CVE-2025-2276 - Ultimate Dashboard <= 3.8.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Modules A…

The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_module_actions function in all versions up to, and including, 3.8.7. This makes it possible for authenticated attackers, with S…

πŸ“… Published: March 25, 2025, 11:22 p.m. πŸ”„ Last Modified: April 8, 2026, 5:35 p.m.

6.4

CVSS3.1

CVE-2025-2302 - Advanced Woo Search <= 3.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via aws_sear…

The Advanced Woo Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's aws_search_terms shortcode in all versions up to, and including, 3.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

πŸ“… Published: March 25, 2025, 11:21 p.m. πŸ”„ Last Modified: April 8, 2026, 5:31 p.m.

9.8

CVSS3.1

CVE-2024-47516 - Pagure: argument injection in pagurerepo.log()

A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.

πŸ“… Published: March 25, 2025, 11:21 p.m. πŸ”„ Last Modified: Aug. 12, 2025, 1:32 p.m.

2.1

CVSS4.0

CVE-2025-30222 - Shescape has potential environment variable exposure on Windows with CMD

Shescape is a simple shell escape library for JavaScript. Versions 1.7.2 through 2.1.1 are vulnerable to potential environment variable exposure on Windows with CMD. This impact users of Shescape on Windows that explicitly configure `shell: 'cmd.exe'` or `shell: true` using any of `quote`/`quoteAll…

πŸ“… Published: March 25, 2025, 11 p.m. πŸ”„ Last Modified: March 27, 2025, 4:45 p.m.
Total resulsts: 343923
Page 5690 of 34,393
Β« previous page Β» next page
Filters