9.3

CVSS4.0

CVE-2013-10055 - Havalite CMS Arbitary File Upload RCE

An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in the upload.php script. The application fails to enforce proper file extension validation and authentication checks, allowing remote attackers to upload malicious PHP files via a cra…

📅 Published: Aug. 1, 2025, 8:39 p.m. 🔄 Last Modified: Aug. 1, 2025, 9:15 p.m.

9.3

CVSS4.0

CVE-2013-10048 - D-Link Devices command.php Unauthenticated RCE

An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, respectively)—due to improper input handling in the unauthenticated command.php endpoint. By sending specially crafted POST requests, a remote attacker c…

📅 Published: Aug. 1, 2025, 8:39 p.m. 🔄 Last Modified: Aug. 1, 2025, 9:15 p.m.

8.7

CVSS4.0

CVE-2013-10050 - D-Link Devices tools_vct.xgi Unauthenticated RCE

An OS command injection vulnerability exists in multiple D-Link routers—confirmed on DIR-300 rev A (v1.05) and DIR-615 rev D (v4.13)—via the authenticated tools_vct.xgi CGI endpoint. The web interface fails to properly sanitize user-supplied input in the pingIp parameter, allowing attackers with va…

📅 Published: Aug. 1, 2025, 8:39 p.m. 🔄 Last Modified: Aug. 1, 2025, 9:15 p.m.

8.6

CVSS4.0

CVE-2013-10059 - D-Link Routers tools_vct.htm OS Command Injection

An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmware version 8.04) via the tools_vct.htm endpoint. The web interface fails to sanitize input passed from the ping_ipaddr parameter to the tools_vct.htm diagnostic interface, allowin…

📅 Published: Aug. 1, 2025, 8:38 p.m. 🔄 Last Modified: Aug. 1, 2025, 9:15 p.m.

8.5

CVSS4.0

CVE-2013-10046 - Agnitum Outpost Internet Security Local Privilege Escalation

A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged user to execute arbitrary code with SYSTEM privileges. The flaw resides in the acs.exe component, which exposes a named pipe that accepts unauthenticated commands. By exploiting a …

📅 Published: Aug. 1, 2025, 8:37 p.m. 🔄 Last Modified: Aug. 1, 2025, 9:15 p.m.

7.3

CVSS3.1

CVE-2025-54595 - Pearcleaner's unauthenticated access to privileged XPC helper allows root command execution

Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged helper tool bundled with the Pearcleaner application. It is registered and activated only after the user approves a system prompt to allow privileged operations. Upon approval, the …

📅 Published: Aug. 1, 2025, 6:06 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:21 p.m.

7.2

CVSS3.1

CVE-2025-54593 - FreshRSS is vulnerable to RCE attacks by authenticated admin

FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the FreshRSS server by modifying the update URL to one they control, and gain code execution after running an update. After successfully executing code, …

📅 Published: Aug. 1, 2025, 6:04 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:32 p.m.

5.7

CVSS3.1

CVE-2025-6015 - Vault Login MFA Bypass of Rate Limiting and TOTP Code Reuse

Vault and Vault Enterprise’s (“Vault”) login MFA rate limits could be bypassed and TOTP tokens could be reused. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

📅 Published: Aug. 1, 2025, 6:03 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:35 p.m.

6.9

CVSS4.0

CVE-2025-54590 - webfinger.js is vulnerable to Blind SSRF attacks through localhost

webfinger.js is a TypeScript-based WebFinger client that runs in both browsers and Node.js environments. In versions 2.8.0 and below, the lookup function accepts user addresses for account checking. However, the ActivityPub specification requires preventing access to localhost services in productio…

📅 Published: Aug. 1, 2025, 6:03 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:39 p.m.

9.3

CVSS3.1

CVE-2025-54574 - Squid's URN Handling can lead to Buffer Overflow

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissi…

📅 Published: Aug. 1, 2025, 6:02 p.m. 🔄 Last Modified: Aug. 1, 2025, 6:43 p.m.
Total resulsts: 304018
Page 6 of 30,402
« previous page » next page
Filters