6.5

CVSS3.1

CVE-2025-0618 -

A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a specially-crafted tamper protection event to the HX service to trigger an exception. This exception will prevent any further tamper protection events from being processed, even after โ€ฆ

๐Ÿ“… Published: April 23, 2025, 6:15 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-0926 -

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for a non-admin user to remove system files causing a boot loop by redirecting a file deletion when recording video. Axis has released a patched version for the highlighted flaw. Please refer to the Axiโ€ฆ

๐Ÿ“… Published: April 23, 2025, 5:22 a.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 5:45 p.m.

6.1

CVSS3.1

CVE-2025-1056 -

Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected location. Axis has released a patched version foโ€ฆ

๐Ÿ“… Published: April 23, 2025, 5:18 a.m. ๐Ÿ”„ Last Modified: Jan. 14, 2026, 5:41 p.m.

7.5

CVSS3.1

CVE-2025-1021 -

Missing authorization vulnerability in synocopy in Synology DiskStation Manager (DSM) before 7.1.1-42962-8, 7.2.1-69057-7 and 7.2.2-72806-3 allows remote attackers to read arbitrary files via unspecified vectors.

๐Ÿ“… Published: April 23, 2025, 2:49 a.m. ๐Ÿ”„ Last Modified: Nov. 17, 2025, 2:10 p.m.

4.3

CVSS3.1

CVE-2025-27581 -

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2025-28018 -

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 8:35 p.m.

6.1

CVSS3.1

CVE-2025-29526 -

A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-28169 -

BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the manufacturer's cloud server unencrypted, allowing attackers to execute a man-in-the-middle attack.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-45429 -

In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may lead to remote arbitrary code execution.

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 3:48 p.m.

7.3

CVSS3.1

CVE-2025-28019 -

TOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component

๐Ÿ“… Published: April 23, 2025, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 8:35 p.m.
Total resulsts: 349182
Page 5691 of 34,919
ยซ previous page ยป next page
Filters