7.8

CVSS3.1

CVE-2025-20631 -

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00397141; Issue ID: MSV-2187.

πŸ“… Published: Feb. 3, 2025, 3:23 a.m. πŸ”„ Last Modified: April 22, 2025, 1:50 p.m.

7.8

CVSS3.1

CVE-2025-20632 -

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00397139; Issue ID: MSV-2188.

πŸ“… Published: Feb. 3, 2025, 3:23 a.m. πŸ”„ Last Modified: April 22, 2025, 1:50 p.m.

8.8

CVSS3.1

CVE-2025-20633 -

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00400889; Issue ID: MSV-2491.

πŸ“… Published: Feb. 3, 2025, 3:23 a.m. πŸ”„ Last Modified: March 18, 2025, 7:15 p.m.

2.3

CVSS4.0

CVE-2025-0974 - MaxD Lightning Module deserialization

A vulnerability was determined in MaxD Lightning Module 4.43/4.44 on OpenCart. This issue affects some unknown processing. Executing a manipulation of the argument li_op/md can lead to deserialization. The attack may be launched remotely. The attack requires a high level of complexity. The exploita…

πŸ“… Published: Feb. 3, 2025, 1 a.m. πŸ”„ Last Modified: April 20, 2026, 3:45 p.m.

5.3

CVSS4.0

CVE-2025-0973 - CmsEasy index.php backAll_action path traversal

A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_action in the library lib/admin/database_admin.php of the file /index.php?case=database&act=backAll&admin_dir=admin&site=default. The manipulation of the argument select[] leads to p…

πŸ“… Published: Feb. 3, 2025, 12:31 a.m. πŸ”„ Last Modified: Feb. 28, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-0972 - Zenvia Movidesk New Ticket cross site scripting

A vulnerability classified as problematic has been found in Zenvia Movidesk up to 25.01.22. This affects an unknown part of the component New Ticket Handler. The manipulation of the argument subject leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been …

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 2:57 p.m.

4.8

CVSS3.1

CVE-2024-53942 -

An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to command injection via the 2.4 GHz and 5 GHz name parameters, allowing a remote attacker to execute arbitrary OS commands on the device (with root-level permissions) via …

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.2

CVSS3.1

CVE-2024-57967 -

PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-34897 -

Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-36437 -

The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity comp…

πŸ“… Published: Feb. 3, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6876 of 34,919
Β« previous page Β» next page
Filters