7.5

CVSS3.1

CVE-2025-29357 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the startIp and endIp parameters at /goform/SetPptpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 1, 2025, 2:15 a.m.

7.5

CVSS3.1

CVE-2025-29359 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the deviceId parameter at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 1, 2025, 2:15 a.m.

7.5

CVSS3.1

CVE-2025-29358 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the firewallEn parameter at /goform/SetFirewallCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 1, 2025, 2:15 a.m.

6.1

CVSS3.1

CVE-2024-55060 -

A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 4:30 p.m.

6.1

CVSS3.1

CVE-2024-57348 -

Cross Site Scripting vulnerability in PecanProject pecan through v.1.8.0 allows a remote attacker to execute arbitrary code via the crafted payload to the hostname, sitegroupid, lat, lon and sitename parameters.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: April 2, 2025, 8:26 p.m.

8.8

CVSS3.1

CVE-2025-25598 -

Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a crafted executable into a scheduled task.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 4:36 p.m.

6.5

CVSS3.1

CVE-2025-25363 -

An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator privileges to execute arbitrary Javascript in context of a user's browser via injecting a crafted payload iโ€ฆ

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 4:43 p.m.

5.3

CVSS3.1

CVE-2024-55198 -

User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users through discrepancies in the responses.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 6:31 p.m.

5.3

CVSS3.1

CVE-2025-28015 -

A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary HTML code via the fname, lname, and contact parameters.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 7:49 p.m.

7.5

CVSS3.1

CVE-2025-29362 -

Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the list parameter at /goform/setPptpUserList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

๐Ÿ“… Published: March 13, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 25, 2025, 2:14 a.m.
Total resulsts: 343948
Page 5831 of 34,395
ยซ previous page ยป next page
Filters