6.1

CVSS3.1

CVE-2025-69429 -

The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploited by attackers to leak or tamper with the internal file system. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 4:40 p.m.

4.3

CVSS3.1

CVE-2025-63372 -

Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents.

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:26 p.m.

5.5

CVSS3.1

CVE-2025-58345 -

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_certif_11ax_mode write operation, leading to …

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 9, 2026, 6:16 p.m.

6.1

CVSS3.1

CVE-2025-70849 -

Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 3:30 p.m.

5.4

CVSS3.1

CVE-2025-69848 -

NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper esca…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 4:08 p.m.

9.8

CVSS3.1

CVE-2025-61506 -

An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of any size to the /upload endpoint.

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:26 p.m.

5.3

CVSS3.1

CVE-2026-1801 - Libsoup: libsoup: http request smuggling via malformed chunk headers

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the soup_filter_input_stream_read_line() logic, where libsoup accepts malformed chunk headers, such as lone line feed (LF) characters instead of the require…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: April 16, 2026, 5:30 p.m.

9.8

CVSS3.1

CVE-2025-67187 -

A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists in the setIpQosRules interface of /lib/cste_modules/firewall.so where the comment parameter is not properly validated for length.

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 10, 2026, 2:14 p.m.

10

CVSS3.1

CVE-2025-10878 -

A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vulnerable to SQL injection, allowing unauthenticated attackers to bypass authentication completely. Successful exploitation grants full admi…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 12, 2026, 5:37 p.m.

6.1

CVSS3.1

CVE-2025-69431 -

The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create a symbolic link to its root directory, insert the drive into the NAS device's slot, and then access the USB drive's directory mounted on the NAS using the Samba…

πŸ“… Published: Feb. 3, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 4:14 p.m.
Total resulsts: 349182
Page 1850 of 34,919
Β« previous page Β» next page
Filters