9.1

CVSS3.1

CVE-2025-45953 -

A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely

๐Ÿ“… Published: April 28, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 6:03 p.m.

6

CVSS3.1

CVE-2022-41871 -

SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.

๐Ÿ“… Published: April 28, 2025, midnight ๐Ÿ”„ Last Modified: May 14, 2025, 6:58 p.m.

9.8

CVSS3.1

CVE-2025-45947 -

An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component

๐Ÿ“… Published: April 28, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 6:59 p.m.

7.2

CVSS3.1

CVE-2015-4582 -

The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.

๐Ÿ“… Published: April 28, 2025, midnight ๐Ÿ”„ Last Modified: April 30, 2025, 7:33 p.m.

6.9

CVSS4.0

CVE-2025-31144 -

Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker may attempt to log in to an arbitrary host via Windows system where the product is running.

๐Ÿ“… Published: April 27, 2025, 11:57 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-27937 -

Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an arbitrary file in the affected product may be obtained by a remote attacker who can log in to the product.

๐Ÿ“… Published: April 27, 2025, 11:56 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2025-26692 -

Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary code may be executed by a remote unauthenticated attacker with the Windows system privilege where the product is running.

๐Ÿ“… Published: April 27, 2025, 11:56 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-3991 - TOTOLINK N150RT formWdsEncrypt buffer overflow

A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boafrm/formWdsEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has beeโ€ฆ

๐Ÿ“… Published: April 27, 2025, 11:31 p.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:31 p.m.

8.7

CVSS4.0

CVE-2025-3990 - TOTOLINK N150RT formVlan buffer overflow

A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this issue is some unknown functionality of the file /boafrm/formVlan. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The expโ€ฆ

๐Ÿ“… Published: April 27, 2025, 11 p.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:31 p.m.

8.7

CVSS4.0

CVE-2025-3989 - TOTOLINK N150RT formStaticDHCP buffer overflow

A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this vulnerability is an unknown functionality of the file /boafrm/formStaticDHCP. The manipulation of the argument Hostname leads to buffer overflow. The attack can be launched remotely. The exploit haโ€ฆ

๐Ÿ“… Published: April 27, 2025, 10:31 p.m. ๐Ÿ”„ Last Modified: May 12, 2025, 7:31 p.m.
Total resulsts: 346631
Page 5396 of 34,664
ยซ previous page ยป next page
Filters