Search Results (30903 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-41572 1 Eyesofnetwork 1 Eyesofnetwork 2025-06-13 9.8 Critical
An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.
CVE-2024-37759 1 Datagear 1 Datagear 2025-06-13 9.8 Critical
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing interface.
CVE-2024-52771 1 Dedebiz 1 Dedebiz 2025-06-13 9.1 Critical
DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.
CVE-2024-52770 1 Dedebiz 1 Dedebiz 2025-06-13 9.8 Critical
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2025-26846 1 Znuny 1 Znuny 2025-06-13 9.8 Critical
An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.
CVE-2025-44830 1 Engineercms Project 1 Engineercms 2025-06-13 9.8 Critical
EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.
CVE-2025-45779 1 Tenda 2 Ac10, Ac10 Firmware 2025-06-13 9.8 Critical
Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.
CVE-2025-44868 1 Wavlink 2 Wl-wn530h4, Wl-wn530h4 Firmware 2025-06-13 9.8 Critical
Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
CVE-2025-45238 1 Qianfox 1 Foxcms 2025-06-12 9.1 Critical
foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.
CVE-2025-44073 1 Seacms 1 Seacms 2025-06-12 9.8 Critical
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
CVE-2025-26844 1 Znuny 1 Znuny 2025-06-12 9.8 Critical
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
CVE-2025-45887 1 Wanglongcn 1 Yifang 2025-06-12 9.1 Critical
Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.
CVE-2025-28200 1 Govicture 2 Rx1800, Rx1800 Firmware 2025-06-12 9.8 Critical
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.
CVE-2025-48187 1 Infiniflow 1 Ragflow 2025-06-12 9.1 Critical
RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.
CVE-2025-47945 1 Donetick 1 Donetick 2025-06-12 9.1 Critical
Donetick an open-source app for managing tasks and chores. Prior to version 0.1.44, the application uses JSON Web Tokens (JWT) for authentication, but the signing secret has a weak default value. While the responsibility is left to the system administrator to change it, this approach is inadequate. The vulnerability is proven by existence of the issue in the live version as well. This issue can result in full account takeover of any user. Version 0.1.44 contains a patch.
CVE-2025-4978 1 Netgear 2 Dgnd3700, Dgnd3700 Firmware 2025-06-12 9.8 Critical
A vulnerability, which was classified as very critical, was found in Netgear DGND3700 1.1.00.15_1.00.15NA. This affects an unknown part of the file /BRS_top.html of the component Basic Authentication. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other products might be affected as well. The vendor was contacted early about this disclosure.
CVE-2024-25191 1 Zihanggao 1 Php-jwt 2025-06-12 9.8 Critical
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.
CVE-2024-24333 1 Totolink 2 A3300r, A3300r Firmware 2025-06-12 9.8 Critical
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.
CVE-2024-24329 1 Totolink 2 A3300r, A3300r Firmware 2025-06-12 9.8 Critical
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.
CVE-2024-24029 1 Jfinalcms Project 1 Jfinalcms 2025-06-12 9.8 Critical
JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.