7.5

CVSS3.1

CVE-2025-29785 - quic-go Has Panic in Path Probe Loss Recovery Handling

quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added in the v0.50.0 release can be used to trigger a nil-pointer dereference by a malicious QUIC client. In order to do so, the attacker first sends valid QUIC packets from different re…

πŸ“… Published: June 2, 2025, 10:44 a.m. πŸ”„ Last Modified: June 2, 2025, 5:32 p.m.

5.3

CVSS4.0

CVE-2025-5441 - Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 setDeviceURL os command injection

A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setDeviceURL of the file /goform/setDeviceURL. The manipulation of the argument DeviceURL le…

πŸ“… Published: June 2, 2025, 10:31 a.m. πŸ”„ Last Modified: June 25, 2025, 6:10 p.m.

9.8

CVSS3.0

CVE-2025-1750 - SQL Injection in run-llama/llama_index

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote cod…

πŸ“… Published: June 2, 2025, 10:04 a.m. πŸ”„ Last Modified: July 31, 2025, 4:08 p.m.

5.3

CVSS4.0

CVE-2025-5440 - Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 NTP os command injection

A vulnerability classified as critical has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function NTP of the file /goform/NTP. The manipulation of the argument manual_year_select/manual_month_select/…

πŸ“… Published: June 2, 2025, 10 a.m. πŸ”„ Last Modified: July 2, 2025, 6:07 p.m.

5.3

CVSS4.0

CVE-2025-5439 - Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 verifyFacebookLike os command injection

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been rated as critical. Affected by this issue is the function verifyFacebookLike of the file /goform/verifyFacebookLike. The manipulation of the ar…

πŸ“… Published: June 2, 2025, 9:31 a.m. πŸ”„ Last Modified: July 2, 2025, 6:08 p.m.

5.3

CVSS4.0

CVE-2025-5438 - Linksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 WPS command injection

A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. Affected by this vulnerability is the function WPS of the file /goform/WPS. The manipulation of the argument PIN leads to…

πŸ“… Published: June 2, 2025, 9 a.m. πŸ”„ Last Modified: July 2, 2025, 6:08 p.m.

8.4

CVSS4.0

CVE-2025-5455 - Possible denial of service when passing malformed data in a URL to qDecodeDataUrl

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:c…

πŸ“… Published: June 2, 2025, 8:46 a.m. πŸ”„ Last Modified: June 2, 2025, 5:32 p.m.

6.9

CVSS4.0

CVE-2025-5437 - Multilaser Sirius RE016 Password Change cstecgi.cgi improper authentication

A vulnerability classified as critical has been found in Multilaser Sirius RE016 MLT1.0. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi of the component Password Change Handler. The manipulation leads to improper authentication. It is possible to launch the attack remotely. The ex…

πŸ“… Published: June 2, 2025, 8:31 a.m. πŸ”„ Last Modified: June 2, 2025, 5:32 p.m.

6.9

CVSS4.0

CVE-2025-5436 - Multilaser Sirius RE016 cstecgi.cgi information disclosure

A vulnerability was found in Multilaser Sirius RE016 MLT1.0. It has been rated as problematic. This issue affects some unknown processing of the file /cgi-bin/cstecgi.cgi. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the p…

πŸ“… Published: June 2, 2025, 8 a.m. πŸ”„ Last Modified: June 2, 2025, 5:32 p.m.

8.8

CVSS3.1

CVE-2025-0358 -

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Device Configuration framework that allowed a privilege escalation, enabling aΒ lower-privileged user to gain administrator privileges.

πŸ“… Published: June 2, 2025, 7:39 a.m. πŸ”„ Last Modified: Jan. 15, 2026, 3:38 p.m.
Total resulsts: 343919
Page 4676 of 34,392
Β« previous page Β» next page
Filters