5.1

CVSS4.0

CVE-2019-25233 - AVE DOMINAplus 1.10.x Cross-Site Request Forgery and XSS Vulnerabilities

AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessi…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2018-25156 - Teradek Cube 7.3.6 Cross-Site Request Forgery Password Change

Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page with a hidden form to submit password change requests to the device's system configuration inte…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2018-25155 - Teradek Slice 7.3.15 Cross-Site Request Forgery via Password Change

Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page that automatically submits password change requests to the device when a logged-in user visit…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.5

CVSS4.0

CVE-2018-25154 - GNU Barcode 0.99 Buffer Overflow in Code 93 Encoding Mechanism

GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

6.9

CVSS4.0

CVE-2018-25153 - GNU Barcode 0.99 Memory Leak Vulnerability in Command Line Processing

GNU Barcode 0.99 contains a memory leak vulnerability in the command line processing function within cmdline.c. Attackers can exploit this vulnerability by providing specially crafted input that causes unfreed memory allocations, potentially leading to denial of service conditions.

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2018-25152 - Ecessa Edge EV150 10.7.4 Cross-Site Request Forgery via User Configuration

Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a form that submits requests to the /cgi-bin/pl_web.cgi/util_configlogin_act endpoint to ad…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2018-25151 - Ecessa WANWorx WVR-30 < 10.7.4 Cross-Site Request Forgery via User Configuration

Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft a malicious web page with a hidden form to create a new superuser account by tricking an authentica…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2018-25150 - Ecessa ShieldLink SL175EHQ 10.7.4 Cross-Site Request Forgery via User Configuration

Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a hidden form to add a superuser account by tricking a logged-in administrator int…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2018-25149 - Microhard Systems IPn4G 1.1.0 Cross-Site Request Forgery via Web Interface

Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated user…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2018-25148 - Microhard Systems IPn4G 1.1.0 Remote Code Execution via Admin Interface

Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, i…

πŸ“… Published: Dec. 24, 2025, 7:27 p.m. πŸ”„ Last Modified: Dec. 24, 2025, 7:27 p.m.
Total resulsts: 324366
Page 7 of 32,437
Β« previous page Β» next page
Filters