Latest CVE Feed
-
3.9
LOWCVE-2025-44657
In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for i... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-44655
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal n... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-44651
In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimited users are connected.... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
7.5
HIGHCVE-2025-44650
In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Denial of Service
-
7.3
HIGHCVE-2025-44647
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1 Aggressive Mode with Pre-Shared Keys to conduct offline att... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2024-55040
Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters.... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-7928
A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical. This issue affects some unknown processing of the file /members/edit_user.php. The manipulation of the argument firstname leads to sql injection. The attack ... Read more
Affected Products : church_donation_system- Published: Jul. 21, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-7927
A vulnerability has been found in PHPGurukul Online Banquet Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/view-user-queries.php. The manipulation of the argument viewid leads to sql injection. Th... Read more
Affected Products : online_banquet_booking_system- Published: Jul. 21, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-46123
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memor... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
9.1
CRITICALCVE-2025-46122
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-46121
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A re... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-46120
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates o... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Path Traversal
-
6.3
MEDIUMCVE-2025-46119
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrato... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-46118
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remot... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-46117
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its ... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-46116
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` vi... Read more
Affected Products : ruckus_unleashed ruckus_zonedirector ruckus_c110 ruckus_e510 ruckus_h320 ruckus_h350 ruckus_h510 ruckus_h550 ruckus_m510 ruckus_m510-jp +32 more products- Published: Jul. 21, 2025
- Modified: Aug. 05, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-43977
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCa... Read more
Affected Products : com.skt.prod.dialer- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2025-43976
The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.Di... Read more
Affected Products : 2ndline- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2025-7926
A vulnerability, which was classified as problematic, was found in PHPGurukul Online Banquet Booking System 1.0. This affects an unknown part of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to cross site scripting.... Read more
Affected Products : online_banquet_booking_system- Published: Jul. 21, 2025
- Modified: Jul. 29, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-7624
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active for Email and SFOS was upgraded from a version older than ... Read more
- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Injection