7.3

CVSS3.1

CVE-2025-43948 -

Codemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as for sorting), which will get executed on the server side.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 2:08 p.m.

0.0

CVE-2025-44201 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: Aug. 15, 2025, 8:36 p.m.

7.8

CVSS3.1

CVE-2025-43950 -

DPMAdirektPro 4.1.5 is vulnerable to DLL Hijacking. It happens by placing a malicious DLL in a directory (in the absence of a legitimate DLL), which is then loaded by the application instead of the legitimate DLL. This causes the malicious DLL to load with the same privileges as the application, th…

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 23, 2025, 2:15 p.m.

9.8

CVSS3.1

CVE-2025-28039 -

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW function through the FileName parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 4:01 p.m.

9.8

CVSS3.1

CVE-2025-28036 -

TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 4:13 p.m.

9.8

CVSS3.1

CVE-2025-28034 -

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost funct…

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 4:18 p.m.

7.3

CVSS3.1

CVE-2025-28033 -

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through …

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 4:19 p.m.

7.3

CVSS3.1

CVE-2025-28029 -

TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in cstecgi.cgi

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:28 p.m.

5.4

CVSS3.1

CVE-2024-53569 -

A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the description parameter.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2023-43958 -

An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code.

πŸ“… Published: April 22, 2025, midnight πŸ”„ Last Modified: May 14, 2025, 1:14 p.m.
Total resulsts: 344690
Page 5255 of 34,469
Β« previous page Β» next page
Filters