5.4

CVSS3.1

CVE-2025-25768 -

MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: April 4, 2025, 3:26 p.m.

7.6

CVSS3.1

CVE-2024-57176 -

An issue in the shiroFilter function of White-Jotter project v0.2.2 allows attackers to execute a directory traversal and access sensitive endpoints via a crafted URL.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: Aug. 21, 2025, 9:51 p.m.

6.5

CVSS3.1

CVE-2025-25507 -

There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 1:37 p.m.

4

CVSS3.1

CVE-2025-25765 -

MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 7:10 p.m.

4.2

CVSS3.1

CVE-2024-55159 -

GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/loginLog/list.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-25875 -

A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /message.php. The attack can use SQL injection to obtain sensitive data.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 6:45 p.m.

8

CVSS3.1

CVE-2025-25769 -

Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: March 28, 2025, 8:08 p.m.

5.1

CVSS3.1

CVE-2025-25772 -

A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 2:43 p.m.

6.5

CVSS3.1

CVE-2025-25604 -

Totolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: April 4, 2025, 3:30 p.m.

6.5

CVSS3.1

CVE-2025-25510 -

Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.

๐Ÿ“… Published: Feb. 21, 2025, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 1:36 p.m.
Total resulsts: 349182
Page 6669 of 34,919
ยซ previous page ยป next page
Filters