Latest CVE Feed
-
9.8
CRITICALCVE-2025-45865
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formDhcpv6s interface.... Read more
- Published: May. 13, 2025
- Modified: May. 15, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-45986
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 werediscovered to contain a command injection vulnerability via the mac paramete... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac2100_az3_firmware bl-ac2100_az3 bl-x10_ac8_firmware bl-x10_ac8 bl-lte300_firmware bl-lte300 bl-f1200_at1_firmware bl-f1200_at1 +6 more products- Published: Jun. 13, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45890
Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter... Read more
Affected Products : novel-plus- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-45858
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.... Read more
- Published: May. 13, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45949
A critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the /loginsystem/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijac... Read more
Affected Products : user_registration_\&_login_and_user_management_system- Published: Apr. 28, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-45798
A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter.... Read more
- Published: May. 08, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45872
zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.... Read more
Affected Products : zrlog- Published: Jul. 01, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Server-Side Request Forgery
-
9.8
CRITICALCVE-2025-45797
TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the NoticeUrl parameter in the setNoticeCfg interface of /lib/cste_modules/system.so.... Read more
- Published: May. 08, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-45488
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the mailex parameter.... Read more
- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45491
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the username parameter.... Read more
- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45607
An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.... Read more
Affected Products : itranswarp- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-45065
employee record management system in php and mysql v1 was discovered to contain a SQL injection vulnerability via the loginerms.php endpoint.... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45042
Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.... Read more
- Published: May. 05, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45612
Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.... Read more
Affected Products : xmall- Published: May. 05, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-45490
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS function via the password parameter.... Read more
- Published: May. 06, 2025
- Modified: May. 13, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-44886
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44881
A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.... Read more
- Published: May. 20, 2025
- Modified: May. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45931
An issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in the bin/goahead file... Read more
- Published: Jun. 30, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-44883
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.... Read more
- Published: May. 20, 2025
- Modified: May. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-44831
EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.... Read more
Affected Products : engineercms- Published: May. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Injection