9.8

CVSS3.1

CVE-2025-43949 -

MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to execute malicious SQL statements that control a web application's database server.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2025-28038 -

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 29, 2025, 4:02 p.m.

9.8

CVSS3.1

CVE-2025-28039 -

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 29, 2025, 4:01 p.m.

7

CVSS3.1

CVE-2025-29547 -

In Rollback Rx Professional 12.8.0.0, the driver file shieldm.sys allows local users to cause a denial of service because of a null pointer dereference from IOCtl 0x96202000.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:08 p.m.

6.5

CVSS3.1

CVE-2025-28031 -

TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 29, 2025, 4:21 p.m.

6.5

CVSS3.1

CVE-2025-29743 -

D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in /goform/delRouting.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:08 p.m.

6.1

CVSS3.1

CVE-2025-26159 -

Laravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify tags can inject malicious JavaScript code in the name field.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:08 p.m.

7.3

CVSS3.1

CVE-2025-43947 -

Codemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can perform, such as modifying the configuration, creating a user, uploading files, etc.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:08 p.m.

7.3

CVSS3.1

CVE-2025-43948 -

Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:08 p.m.

5.4

CVSS3.1

CVE-2024-53568 -

A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter.

๐Ÿ“… Published: April 22, 2025, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:15 p.m.
Total resulsts: 291908
Page 86 of 29,191
ยซ previous page ยป next page
Filters