5.4

CVSS3.1

CVE-2025-45236 -

A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 18, 2025, 7:54 p.m.

6.5

CVSS3.1

CVE-2024-57234 -

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: May 7, 2025, 4:42 p.m.

6.5

CVSS3.1

CVE-2024-57230 -

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: May 7, 2025, 4:41 p.m.

9.8

CVSS3.1

CVE-2025-45042 -

Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: May 7, 2025, 4:39 p.m.

7.5

CVSS3.1

CVE-2025-45617 -

Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 17, 2025, 3:03 p.m.

7.5

CVSS3.1

CVE-2025-45613 -

Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 14, 2025, 8:47 p.m.

8.8

CVSS3.1

CVE-2025-45322 -

kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: May 7, 2025, 4:40 p.m.

7.7

CVSS3.1

CVE-2025-45242 -

Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 2:12 p.m.

9.8

CVSS3.1

CVE-2025-44072 -

SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_manager.php.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: May 13, 2025, 8:05 p.m.

8.1

CVSS3.1

CVE-2025-28062 -

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.

๐Ÿ“… Published: May 5, 2025, midnight ๐Ÿ”„ Last Modified: June 17, 2025, 2:13 p.m.
Total resulsts: 346667
Page 5305 of 34,667
ยซ previous page ยป next page
Filters