Latest CVE Feed
-
6.5
MEDIUMCVE-2025-4901
A vulnerability classified as problematic was found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this vulnerability is the function sub_41E304 of the file /H5/state_view.data of the component HTTP Endpoint. The manipulation leads to information d... Read more
- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-4756
A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been declared as problematic. This vulnerability affects unknown code of the file /H5/restart.asp. The manipulation leads to denial of service. The attack can be initiated remotely... Read more
- Published: May. 16, 2025
- Modified: May. 21, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2025-4902
A vulnerability, which was classified as problematic, has been found in D-Link DI-7003GV2 24.04.18D1 R(68125). Affected by this issue is the function sub_48F4F0 of the file /H5/versionupdate.data. The manipulation leads to information disclosure. The atta... Read more
- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2025-3878
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output escaping o... Read more
Affected Products : sms_alert_order_notifications- Published: May. 10, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-3876
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to, and including, 3.8.1. This makes it p... Read more
Affected Products : sms_alert_order_notifications- Published: May. 10, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2024-48150
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.... Read more
- Published: Oct. 14, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-4911
A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possi... Read more
Affected Products : zoo_management_system- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-36832
A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The vulnerability occurs in the /bin/webs binary of the firmware. When /bin/webs receive... Read more
- Published: Dec. 17, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2024-44411
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.... Read more
- Published: Sep. 09, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2024-57045
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.... Read more
- Published: Feb. 18, 2025
- Modified: May. 21, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-34950
D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.... Read more
- Published: May. 14, 2024
- Modified: May. 21, 2025
-
5.4
MEDIUMCVE-2024-33111
D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.... Read more
- Published: May. 06, 2024
- Modified: May. 21, 2025
-
7.5
HIGHCVE-2024-33112
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.... Read more
- Published: May. 06, 2024
- Modified: May. 21, 2025
-
5.3
MEDIUMCVE-2024-33113
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.... Read more
- Published: May. 06, 2024
- Modified: May. 21, 2025
-
9.1
CRITICALCVE-2024-33110
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.... Read more
- Published: May. 06, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2025-4925
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /expense-monthwise-reports-detailed.php. The manipulation of the argument from... Read more
Affected Products : daily_expense_tracker_system- Published: May. 19, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-33345
D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi, which allows remote attackers to cause a Denial of Service (DoS) via a crafted input.... Read more
- Published: Apr. 29, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2024-33344
D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.... Read more
- Published: Apr. 26, 2024
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2024-33343
D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.... Read more
- Published: Apr. 26, 2024
- Modified: May. 21, 2025
-
7.5
HIGHCVE-2024-33342
D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.... Read more
- Published: Apr. 26, 2024
- Modified: May. 21, 2025