6.5

CVSS3.1

CVE-2025-29218 -

Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

๐Ÿ“… Published: March 20, 2025, midnight ๐Ÿ”„ Last Modified: March 26, 2025, 6:23 p.m.

10

CVSS3.1

CVE-2025-26852 -

DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.

๐Ÿ“… Published: March 20, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 6:59 p.m.

6.5

CVSS3.1

CVE-2025-29217 -

Tenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

๐Ÿ“… Published: March 20, 2025, midnight ๐Ÿ”„ Last Modified: March 25, 2025, 5:38 p.m.

7.5

CVSS3.1

CVE-2025-29149 -

Tenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.

๐Ÿ“… Published: March 20, 2025, midnight ๐Ÿ”„ Last Modified: March 27, 2025, 3:26 p.m.

7.5

CVSS3.1

CVE-2025-29121 -

A vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file form_fast_setting_wifi_set. Using the timeZone parameter causes a stack-based buffer overflow.

๐Ÿ“… Published: March 20, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 7:34 p.m.

7.5

CVSS3.1

CVE-2024-57440 -

D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webproc cgi

๐Ÿ“… Published: March 20, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 20, 2026, 8:15 p.m.

6.1

CVSS3.1

CVE-2024-48591 -

Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing.

๐Ÿ“… Published: March 20, 2025, midnight ๐Ÿ”„ Last Modified: April 1, 2025, 8:19 p.m.

7.5

CVSS3.1

CVE-2025-25758 -

An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml

๐Ÿ“… Published: March 20, 2025, midnight ๐Ÿ”„ Last Modified: April 1, 2025, 8:25 p.m.

7.5

CVSS3.1

CVE-2025-29214 -

Tenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.

๐Ÿ“… Published: March 20, 2025, midnight ๐Ÿ”„ Last Modified: March 25, 2025, 5:37 p.m.

8.8

CVSS4.0

CVE-2025-27774 - Applio allows SSRF and file write in model_download.py

Applio is a voice conversion tool. Versions 3.2.7 and prior are vulnerable to server-side request forgery (SSRF) and file write in `model_download.py` (line 156 in 3.2.7). The blind SSRF allows for sending requests on behalf of Applio server and can be leveraged to probe for other vulnerabilities oโ€ฆ

๐Ÿ“… Published: March 19, 2025, 8:42 p.m. ๐Ÿ”„ Last Modified: Aug. 1, 2025, 12:55 a.m.
Total resulsts: 349182
Page 6300 of 34,919
ยซ previous page ยป next page
Filters