4

CVSS3.1

CVE-2025-32996 - http-proxy-middleware: Always-Incorrect Control Flow Implementation in http-proxy-middleware

In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 21, 2025, 2:43 p.m.

4.6

CVSS3.1

CVE-2025-22903 -

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the pin parameter in the function setWiFiWpsConfig.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 4:55 p.m.

4.6

CVSS3.1

CVE-2025-25458 -

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serverName2.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 4:43 p.m.

6.5

CVSS3.1

CVE-2025-28142 -

Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: May 1, 2025, 2:26 p.m.

6.8

CVSS3.1

CVE-2025-27892 -

Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 4:30 p.m.

6.5

CVSS3.1

CVE-2020-18243 -

SQL injection vulnerability found in Enricozab CMS v.1.0 allows a remote attacker to execute arbitrary code via /hdo/hdo-view-case.php.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 6:43 p.m.

4.6

CVSS3.1

CVE-2025-25453 -

Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via serviceName2.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 22, 2025, 4:43 p.m.

7.2

CVSS3.1

CVE-2024-50960 -

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 25, 2025, 6:35 p.m.

6

CVSS3.1

CVE-2025-32987 - From CVEorg collector

Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2025-29280 -

Stored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface allows an attacker to insert and execute arbitrary malicious code.

๐Ÿ“… Published: April 15, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 3:19 p.m.
Total resulsts: 349182
Page 5885 of 34,919
ยซ previous page ยป next page
Filters