9.8

CVSS3.1

CVE-2025-25221 -

The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.

πŸ“… Published: Feb. 18, 2025, 12:10 a.m. πŸ”„ Last Modified: Sept. 15, 2025, 5:48 p.m.

7.1

CVSS3.1

CVE-2024-57259 -

sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for squashfs directory listing because the path separator is not considered in a size calculation.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

8

CVSS3.1

CVE-2025-25894 -

An OS command injection vulnerability was discovered in D-Link DSL-3782 v1.01 via the samba_wg and samba_nbn parameters. This vulnerability allows attackers to execute arbitrary operating system (OS) commands via a crafted packet.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 3:46 p.m.

6.4

CVSS3.1

CVE-2022-41545 -

The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authenticates users via basic authentication, with an HTTP header containing a base64 value of the plaintext username and password. Because the web server also does not utilize transpor…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: June 6, 2025, 6:01 p.m.

9.9

CVSS3.1

CVE-2024-39327 -

Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing in an illegitimate way.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: March 17, 2025, 10:15 p.m.

8.8

CVSS3.1

CVE-2024-57046 -

A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 6:11 p.m.

6.5

CVSS3.1

CVE-2025-22919 -

A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

7.1

CVSS3.1

CVE-2024-57256 -

An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 variable) via a crafted ext4 filesystem with an inode size of 0xffffffff, resulting in a malloc of zero and resultant memory overwrite.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

7.8

CVSS3.1

CVE-2025-21703 - netem: Update sch->q.qlen before qdisc_tree_reduce_backlog()

In the Linux kernel, the following vulnerability has been resolved: netem: Update sch->q.qlen before qdisc_tree_reduce_backlog() qdisc_tree_reduce_backlog() notifies parent qdisc only if child qdisc becomes empty, therefore we need to reduce the backlog of the child qdisc before calling it. Other…

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 8:39 a.m.

5.7

CVSS3.1

CVE-2025-25892 -

A buffer overflow vulnerability was discovered in D-Link DSL-3782 v1.01 via the sstartip, sendip, dstartip, and dendip parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.

πŸ“… Published: Feb. 18, 2025, midnight πŸ”„ Last Modified: May 2, 2025, 3:46 p.m.
Total resulsts: 343921
Page 6181 of 34,393
Β« previous page Β» next page
Filters