8.7

CVSS4.0

CVE-2019-25239 - V-SOL GPON/EPON OLT Platform 2.03 Unauthenticated Configuration Download

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potenti…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2019-25238 - V-SOL GPON/EPON OLT Platform 2.03 Cross-Site Request Forgery Vulnerability

V-SOL GPON/EPON OLT Platform 2.03 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to create admin users, enable SSH, or modify system settings by tricking authenticated administ…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2019-25237 - V-SOL GPON/EPON OLT Platform 2.03 Privilege Escalation via User Role Parameter

V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to integer value '…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2019-25236 - iSeeQ Hybrid DVR WH-H4 1.03R Unauthenticated Live Stream Disclosure

iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get_jpeg endpoint without authentication.

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.8

CVSS4.0

CVE-2019-25235 - Smartwares HOME easy 1.0.9 Client-Side Authentication Bypass via Web Pages

Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system i…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2019-25234 - Carlo Gavazzi SmartHouse Webapp 6.5.33 Cross-Site Request Forgery and XSS

SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious script…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2019-25233 - AVE DOMINAplus 1.10.x Cross-Site Request Forgery and XSS Vulnerabilities

AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessi…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2018-25156 - Teradek Cube 7.3.6 Cross-Site Request Forgery Password Change

Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page with a hidden form to submit password change requests to the device's system configuration inte…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2018-25155 - Teradek Slice 7.3.15 Cross-Site Request Forgery via Password Change

Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page that automatically submits password change requests to the device when a logged-in user visit…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.5

CVSS4.0

CVE-2018-25154 - GNU Barcode 0.99 Buffer Overflow in Code 93 Encoding Mechanism

GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.
Total resulsts: 324362
Page 6 of 32,437
Β« previous page Β» next page
Filters