Latest CVE Feed
-
8.1
HIGHCVE-2024-57036
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-28031
TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a hardcoded password for the telnet service in product.ini.... Read more
Affected Products : a810r_firmware- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2025-28030
TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function.... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-28024
TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi... Read more
- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2025-28032
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the ... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware a3100r a3000ru a830r a800r +2 more products- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2025-28033
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth buffer overflow vulnera... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware a3100r a3000ru a830r a800r +2 more products- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Denial of Service
-
9.8
CRITICALCVE-2025-28034
TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command executio... Read more
Affected Products : a830r_firmware a3100r_firmware a950rg_firmware a800r_firmware a3000ru_firmware a810r_firmware a3100r a3000ru a830r a800r +2 more products- Published: Apr. 22, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Injection
-
2.9
LOWCVE-2025-46656
python-markdownify (aka markdownify) before 0.14.1 allows large headline prefixes such as <h9999999> in addition to <h1> through <h6>. This causes memory consumption.... Read more
Affected Products : markdownify- Published: Apr. 26, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Denial of Service
-
4.9
MEDIUMCVE-2025-46655
CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error i... Read more
Affected Products : codimd- Published: Apr. 26, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
3.1
LOWCVE-2025-46653
Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographically secure." (Also, there is a scenario in which only t... Read more
Affected Products : formidable- Published: Apr. 26, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
8.1
HIGHCVE-2025-31686
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.... Read more
Affected Products : open_social- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
9.1
CRITICALCVE-2025-31685
Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 0.0.0 before 12.3.11, from 12.4.0 before 12.4.10.... Read more
Affected Products : open_social- Published: Mar. 31, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2024-53636
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.... Read more
Affected Products :- Published: Apr. 26, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2022-45015
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Footer field.... Read more
Affected Products : wbce_cms- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-45014
A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Results Header field.... Read more
Affected Products : wbce_cms- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-45013
A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.... Read more
Affected Products : wbce_cms- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
4.8
MEDIUMCVE-2022-45012
A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field.... Read more
Affected Products : wbce_cms- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
7.8
HIGHCVE-2022-44830
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.... Read more
Affected Products : event_registration_application- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
6.5
MEDIUMCVE-2022-44788
An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESSIONID cookie that is issued by the server at the first visit, the cookie value is not updated after a successful login.... Read more
Affected Products : appalti_\&_contratti- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025
-
6.1
MEDIUMCVE-2022-44787
An issue was discovered in Appalti & Contratti 9.12.2. The web applications are vulnerable to a Reflected Cross-Site Scripting issue. The idPagina parameter is reflected inside the server response without any HTML encoding, resulting in XSS when the victi... Read more
Affected Products : appalti_\&_contratti- Published: Nov. 21, 2022
- Modified: Apr. 29, 2025