7.6

CVSS3.1

CVE-2025-29452 -

An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

6.3

CVSS3.1

CVE-2025-29722 -

A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.2

CVSS3.1

CVE-2025-29180 -

In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

9.8

CVSS3.1

CVE-2025-29042 -

An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 18, 2025, 3:12 p.m.

6.5

CVSS3.1

CVE-2025-28101 -

An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

3.3

CVSS3.1

CVE-2025-26269 -

DragonflyDB Dragonfly through 1.28.2 allows authenticated users to cause a denial of service (daemon crash) via a Lua library command that references a large negative integer.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

3.3

CVSS3.1

CVE-2025-26268 -

DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

8.4

CVSS3.1

CVE-2024-55211 -

An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.

7.8

CVSS3.1

CVE-2021-47670 - can: peak_usb: fix use after free bugs

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the peak_usb_netif_rx_ni(). Reordering the line…

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 6:41 p.m.

7.2

CVSS3.1

CVE-2025-29039 -

An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x41dda8

πŸ“… Published: April 17, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:21 p.m.
Total resulsts: 291045
Page 53 of 29,105
Β« previous page Β» next page
Filters