9.8

CVSS3.1

CVE-2025-0456 - NetVision Information airPASS - Missing Authentication

The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access the specific administrative functionality to retrieve * all accounts and passwords.

πŸ“… Published: Jan. 16, 2025, 1:34 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-0455 - NetVision Information airPASS - SQL injection

The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

πŸ“… Published: Jan. 16, 2025, 1:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-57581 -

Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: March 18, 2025, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-22912 -

RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:43 p.m.

9.8

CVSS3.1

CVE-2025-22907 -

RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:43 p.m.

9.8

CVSS3.1

CVE-2025-22904 -

RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:44 p.m.

3.5

CVSS3.1

CVE-2024-57611 -

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2025, 8:09 p.m.

9.8

CVSS3.1

CVE-2025-22916 -

RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: April 9, 2025, 6:42 p.m.

4.6

CVSS3.1

CVE-2024-40513 -

An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload image function.

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: Sept. 30, 2025, 9:20 p.m.

8.7

CVSS3.1

CVE-2024-54660 -

A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the databas…

πŸ“… Published: Jan. 16, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346554
Page 6827 of 34,656
Β« previous page Β» next page
Filters