8

CVSS3.1

CVE-2025-25610 -

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 3:37 p.m.

6.5

CVSS3.1

CVE-2025-25478 -

The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s source code, exposing sensitive information such as the database password.

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 7:30 p.m.

5.4

CVSS3.1

CVE-2025-25476 -

A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious XSS payload as a notification type or notification component.

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 7:30 p.m.

5.1

CVSS3.1

CVE-2025-26047 -

Loggrove v1.0 is vulnerable to SQL Injection in the read.py file.

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: June 12, 2025, 8:17 p.m.

8

CVSS3.1

CVE-2025-25609 -

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup interface of /bin/boa

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 3, 2025, 3:37 p.m.

9.6

CVSS3.1

CVE-2025-25379 -

Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2025, 8:10 p.m.

4.8

CVSS3.1

CVE-2025-25431 -

Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 1:55 p.m.

6.8

CVSS3.1

CVE-2024-44754 -

Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate attackers to inject modified firmware into any other Minut M2 product via USB.

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-25916 -

wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: April 29, 2025, 4:53 p.m.

8.4

CVSS3.1

CVE-2025-25723 -

Buffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.

๐Ÿ“… Published: Feb. 28, 2025, midnight ๐Ÿ”„ Last Modified: Sept. 25, 2025, 1:27 p.m.
Total resulsts: 349182
Page 6519 of 34,919
ยซ previous page ยป next page
Filters