8.8

CVSS3.1

CVE-2025-70031 -

An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: April 1, 2026, 3:39 p.m.

5.3

CVSS3.1

CVE-2025-70040 -

An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allows an attacker to obtain sensitive information.

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: March 11, 2026, 1:53 p.m.

7.5

CVSS3.1

CVE-2025-70238 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: March 11, 2026, 8:02 p.m.

5.4

CVSS3.1

CVE-2025-70033 -

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: April 1, 2026, 3:40 p.m.

5.4

CVSS3.1

CVE-2025-70060 -

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v1.12.0.

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: March 13, 2026, 4:45 p.m.

4.8

CVSS3.1

CVE-2025-70973 -

ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in,โ€ฆ

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: April 7, 2026, 4:04 p.m.

9.8

CVSS3.1

CVE-2025-70039 -

An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1223.

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: March 13, 2026, 4:44 p.m.

7.5

CVSS3.1

CVE-2025-70250 -

Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: March 11, 2026, 8:01 p.m.

9.8

CVSS3.1

CVE-2025-70046 -

An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master.

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: March 13, 2026, 8:02 p.m.

7.5

CVSS3.1

CVE-2026-30140 - Unauthenticated Router Configuration File Disclosure due to Incorrect Access Control

An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive information disclosure and pโ€ฆ

๐Ÿ“… Published: March 9, 2026, midnight ๐Ÿ”„ Last Modified: April 16, 2026, 4:15 a.m.
Total resulsts: 349182
Page 1248 of 34,919
ยซ previous page ยป next page
Filters