6.5

CVSS3.1

CVE-2025-45492 -

Netgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the Iface parameter in the action_wireless function.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 8:19 p.m.

6.5

CVSS3.1

CVE-2025-4374 - Quay: incorrect privilege assignment

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: Feb. 27, 2026, 4:40 p.m.

6.5

CVSS3.1

CVE-2025-45487 -

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.InternetConnection function.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 8:19 p.m.

9.8

CVSS3.1

CVE-2025-44899 -

There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, the manipulation of the parameter shareSpeed leads to stack overflow.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: June 4, 2025, 5:25 p.m.

5.6

CVSS3.1

CVE-2025-47256 -

Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-26262 -

An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a file that contains a crafted filename.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-45490 -

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 8:19 p.m.

9.8

CVSS3.1

CVE-2025-45491 -

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 8:19 p.m.

5.5

CVSS3.1

CVE-2025-45250 -

MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: June 27, 2025, 3:33 p.m.

9.8

CVSS3.1

CVE-2025-44073 -

SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.

๐Ÿ“… Published: May 6, 2025, midnight ๐Ÿ”„ Last Modified: June 12, 2025, 5:09 p.m.
Total resulsts: 346543
Page 5281 of 34,655
ยซ previous page ยป next page
Filters