8.8

CVSS3.1

CVE-2025-68719 -

KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and maintains an active session, an attacker can directly query the backup endpoint and download a full configuration archive. This archive contains sensitive files such as /etc/shadow, e…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Feb. 2, 2026, 4:28 p.m.

9.8

CVSS3.1

CVE-2025-66913 -

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than C…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 30, 2026, 1:06 a.m.

4.8

CVSS3.1

CVE-2026-0716 - Libsoup: out-of-bounds read in libsoup websocket frame processing

A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applicati…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: April 18, 2026, 6:30 a.m.

7.5

CVSS3.1

CVE-2025-50334 - technitium-dns-server: From CVEorg collector

An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting component

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 12, 2026, 6:39 p.m.

9.8

CVSS3.1

CVE-2025-61548 -

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without proper parameterizati…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:16 p.m.

8.7

CVSS3.1

CVE-2025-63611 -

Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the admin viewer (/admin/complaint-details.php?cid=<id>). When an administrator opens the complaint, inj…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 12, 2026, 6:45 p.m.

9.1

CVSS3.1

CVE-2025-68715 -

An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless settings directly, leading…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 30, 2026, 1:04 a.m.

6.1

CVSS3.1

CVE-2025-61549 -

Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). Unsanitized user input is reflected in HTTP responses without proper HTML encoding or escaping. This allow…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:16 p.m.

9.8

CVSS3.1

CVE-2025-67325 -

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Jan. 30, 2026, 1:06 a.m.

5.4

CVSS3.1

CVE-2025-61550 -

Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/TemplatePreview.aspx endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). User-supplied input is stored and later rendered in HTML pages without p…

📅 Published: Jan. 8, 2026, midnight 🔄 Last Modified: Feb. 10, 2026, 6:16 p.m.
Total resulsts: 348200
Page 2139 of 34,820
« previous page » next page
Filters