8.7

CVSS4.0

CVE-2025-7805 - Tenda FH451 PPTPUserSetting fromPptpUserSetting stack-based overflow

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit hโ€ฆ

๐Ÿ“… Published: July 18, 2025, 7:32 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 7:32 p.m.

5.1

CVSS4.0

CVE-2025-7803 - descreekert wx-discuz wx.php validToken cross site scripting

A vulnerability was found in descreekert wx-discuz up to 12bd4745c63ec203cb32119bf77ead4a923bf277. It has been classified as problematic. This affects the function validToken of the file /wx.php. The manipulation of the argument echostr leads to cross site scripting. It is possible to initiate the โ€ฆ

๐Ÿ“… Published: July 18, 2025, 7:14 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 7:14 p.m.

5.1

CVSS4.0

CVE-2025-7802 - PHPGurukul Complaint Management System complaint-search.php cross site scripting

A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/complaint-search.php. The manipulation of the argument Search leads to cross site scripting. The attack may be launched remoโ€ฆ

๐Ÿ“… Published: July 18, 2025, 7:02 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 7:15 p.m.

5.4

CVSS3.1

CVE-2025-33014 - IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4ย uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victโ€ฆ

๐Ÿ“… Published: July 18, 2025, 6:51 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2025-7801 - BossSoft CRM HNDCBas_customPrmSearchDtl.jsp sql injection

A vulnerability has been found in BossSoft CRM 6.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /crm/module/HNDCBas_customPrmSearchDtl.jsp. The manipulation of the argument cstid leads to sql injection. The attack can be launched remotely. The eโ€ฆ

๐Ÿ“… Published: July 18, 2025, 6:44 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 7:15 p.m.

5.1

CVSS4.0

CVE-2025-7800 - cgpandey hotelmis HTTP GET Request admin.php cross site scripting

A vulnerability classified as problematic was found in cgpandey hotelmis up to c572198e6c4780fccc63b1d3e8f3f72f825fc94e. This vulnerability affects unknown code of the file admin.php of the component HTTP GET Request Handler. The manipulation of the argument Search leads to cross site scripting. Thโ€ฆ

๐Ÿ“… Published: July 18, 2025, 6:32 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 7:15 p.m.

5.3

CVSS4.0

CVE-2025-7798 - Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System companyManage sql โ€ฆ

A vulnerability classified as critical has been found in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System up to 8.2. This affects an unknown part of the file /admin/system/structure/getdirectorydata/web/baseinfo/companyManage. The manipulation of the argument Strucctโ€ฆ

๐Ÿ“… Published: July 18, 2025, 6:14 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 7:15 p.m.

6.9

CVSS4.0

CVE-2025-7797 - GPAC dash_client.c gf_dash_download_init_segment null pointer dereference

A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. The manipulation of the argument base_init_url leads to null pointer dereference. The attack may be launchedโ€ฆ

๐Ÿ“… Published: July 18, 2025, 5:44 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 6:15 p.m.

8.7

CVSS4.0

CVE-2025-7796 - Tenda FH451 PPTPDClient fromPptpUserAdd stack-based overflow

A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserAdd of the file /goform/PPTPDClient. The manipulation of the argument Username leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploitโ€ฆ

๐Ÿ“… Published: July 18, 2025, 5:32 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 6:17 p.m.

8.7

CVSS4.0

CVE-2025-7795 - Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The โ€ฆ

๐Ÿ“… Published: July 18, 2025, 5:14 p.m. ๐Ÿ”„ Last Modified: July 18, 2025, 6:15 p.m.
Total resulsts: 302394
Page 1 of 30,240
ยป next page
Filters