Latest CVE Feed
-
7.1
HIGHCVE-2025-48241
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D allows Reflected XSS. This issue affects Verge3D: from n/a through 4.9.3.... Read more
Affected Products : verge3d- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-48275
Missing Authorization vulnerability in dastan800 Visual Header allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Visual Header: from n/a through 1.3.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-5114
A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affects the function Edit of the file /index.php?m=editor&f=edit&filePath=cGhhcjovLy9ldGMvcGFzc3dk&action=edit of the component Committer. Th... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-48287
Deserialization of Untrusted Data vulnerability in Pagaleve Pix 4x sem juros - Pagaleve allows Object Injection.This issue affects Pix 4x sem juros - Pagaleve: from n/a through 1.6.9.... Read more
Affected Products :- Published: May. 23, 2025
- Modified: May. 23, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-4827
A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4829
A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this vulnerability is the function sub_40BE30 of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulati... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4830
A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this issue is some unknown functionality of the file /boafrm/formSysCmd of the component HTTP POST Request Handler. T... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4831
A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formSiteSurveyProfile of the component HTTP POST Request Handler. The manipulation of... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4832
A vulnerability has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formDosCfg of the component HTTP POST Request Handler. The manipulation of th... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4833
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This issue affects some unknown processing of the file /boafrm/formNtp of the component HTTP POST Request Handler. The manipulation of the arg... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4834
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been classified as critical. Affected is an unknown function of the file /boafrm/formSetLg of the component HTTP POST Request Handler. The manipulation of the arg... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4835
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWlanRedirect of the component HTTP POST Request Hand... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4826
A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The ma... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4825
A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument s... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4824
A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the argument submit-... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-4823
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is the function submit-url of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The... Read more
- Published: May. 17, 2025
- Modified: May. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2024-25502
Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the download_backup.php component.... Read more
Affected Products : flusity- Published: Feb. 15, 2024
- Modified: May. 23, 2025
-
6.1
MEDIUMCVE-2024-25166
Cross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfile action parameter in the controller.php file.... Read more
Affected Products : 71cms- Published: Feb. 27, 2024
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2023-41506
An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.... Read more
- Published: Feb. 27, 2024
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2024-25400
Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request to a PHP file that only contains a class, without any mechanism for accepting external input, an... Read more
Affected Products : subrion- Published: Feb. 27, 2024
- Modified: May. 23, 2025