CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2025-49088

    Last Modified: 5 Jan 2026

    Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a crafted calendar invite, leading to a denial of service.

    Published: 25 Dec 2025
    7.4
    High

    CVE-2025-68922

    Last Modified: 15 Apr 2026

    OpenOps before 0.6.11 allows remote code execution in the Terraform block.

    Published: 24 Dec 2025
    5.5
    Medium

    CVE-2025-15073

    Last Modified: 24 Feb 2026

    A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 24 Dec 2025
    8.9
    High

    CVE-2025-68920

    Last Modified: 15 Apr 2026

    C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite files on the local system, or retrieve arbitrary files from the local system.

    Published: 24 Dec 2025
    5.6
    Medium

    CVE-2025-68919

    Last Modified: 15 Apr 2026

    Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/authority other than ETERNUS SF Admin, allows an attacker to potentially affect system confidentiality, integrity, and availability.

    Published: 24 Dec 2025
    6.4
    Medium

    CVE-2025-68917

    Last Modified: 15 Apr 2026

    ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.

    Published: 24 Dec 2025
    9.3
    Critical

    CVE-2025-8769

    Last Modified: 15 Apr 2026

    Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improper input validation, an attacker can inject arbitrary Perl code through a crafted HTTP request, leading to remote code execution on the server.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2025-3232

    Last Modified: 15 Apr 2026

    A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands.

    Published: 24 Dec 2025
    9.1
    Critical

    CVE-2025-68916

    Last Modified: 5 Jan 2026

    Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

    Published: 24 Dec 2025
    5.5
    Medium

    CVE-2025-68915

    Last Modified: 2 Jan 2026

    Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.

    Published: 24 Dec 2025
    6.5
    Medium

    CVE-2025-68914

    Last Modified: 2 Jan 2026

    Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.

    Published: 24 Dec 2025
    7.1
    High

    CVE-2019-25258

    Last Modified: 5 Mar 2026

    LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers to read arbitrary files through unverified 'suffix' and 'fileVersion' parameters. Attackers can exploit directory traversal techniques in /thumbnail and /convertpdf endpoints to access sensitive system files like win.ini and /etc/passwd by manipulating path traversal sequences.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2019-25257

    Last Modified: 15 Apr 2026

    LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to manipulate binary paths when changing system settings. Attackers can exploit these vulnerabilities by modifying configuration parameters like antivirus.command, ocr.Tesseract.path, and other system paths to execute arbitrary system commands with elevated privileges.

    Published: 24 Dec 2025
    7.1
    High

    CVE-2019-25256

    Last Modified: 28 Jul 2026

    VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows attackers to access arbitrary system files through unvalidated 'ID' parameters. Attackers can exploit multiple Perl scripts like downloadsys.pl to read sensitive files by manipulating directory path traversal in download requests.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2019-25255

    Last Modified: 28 Jul 2026

    VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2019-25254

    Last Modified: 7 Apr 2026

    KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft malicious web pages that automatically submit forms to add new admin accounts with predefined credentials when a logged-in user visits the page.

    Published: 24 Dec 2025
    7.1
    High

    CVE-2019-25253

    Last Modified: 14 Jan 2026

    KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malicious XML file with external entity references to retrieve sensitive configuration data like database credentials through an out-of-band channel attack.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2019-25252

    Last Modified: 5 Mar 2026

    Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft malicious web pages that automatically submit password change requests to the device when a logged-in administrator visits the page.

    Published: 24 Dec 2025
    6.9
    Medium

    CVE-2019-25251

    Last Modified: 15 Jul 2026

    Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows attackers to manipulate GET parameters 'url' and 'xml_url'. Attackers can exploit this flaw to bypass firewalls, initiate network enumeration, and potentially trigger external HTTP requests to arbitrary destinations.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2019-25250

    Last Modified: 15 Apr 2026

    Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages that trigger unauthorized configuration changes by exploiting predictable URL actions when a logged-in user visits the site.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2019-25249

    Last Modified: 15 Apr 2026

    devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2019-25248

    Last Modified: 15 Apr 2026

    Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve the camera's RTSP stream by exploiting the lack of authentication in the video access mechanism.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2019-25247

    Last Modified: 15 Apr 2026

    Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft a malicious web page with a hidden form to add an admin user by tricking a logged-in user into submitting the form.

    Published: 24 Dec 2025
    7.1
    High

    CVE-2019-25246

    Last Modified: 15 Apr 2026

    Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. Attackers can exploit the fileread script or SendCGICMD API to access sensitive files like /etc/passwd and /etc/issue by supplying absolute file paths.

    Published: 24 Dec 2025
    8.5
    High

    CVE-2019-25245

    Last Modified: 15 Apr 2026

    Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files due to improper permission settings. Attackers can exploit the 'M' or 'C' flags for 'Authenticated Users' group to replace the DashBoard.exe binary with a malicious executable.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2019-25244

    Last Modified: 15 Apr 2026

    Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site request forgery to change passwords and inject stored cross-site scripting payloads through unvalidated GET parameters.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2019-25243

    Last Modified: 15 Jul 2026

    FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2019-25242

    Last Modified: 5 Mar 2026

    FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change administrator passwords, add new admin users, or open access control doors by tricking authenticated users into loading a specially crafted webpage.

    Published: 24 Dec 2025
    9.8
    Critical

    CVE-2019-25241

    Last Modified: 15 Jul 2026

    FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2019-25240

    Last Modified: 15 Apr 2026

    Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2019-25239

    Last Modified: 15 Apr 2026

    V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potentially enabling authentication bypass and system access.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2019-25238

    Last Modified: 15 Apr 2026

    V-SOL GPON/EPON OLT Platform 2.03 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to create admin users, enable SSH, or modify system settings by tricking authenticated administrators into loading a specially crafted page.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2019-25237

    Last Modified: 15 Apr 2026

    V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to integer value '1' to elevate their privileges.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2019-25236

    Last Modified: 15 Apr 2026

    iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get_jpeg endpoint without authentication.

    Published: 24 Dec 2025
    8.8
    High

    CVE-2019-25235

    Last Modified: 15 Apr 2026

    Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to access administrative web pages by disabling JavaScript. Attackers can navigate to multiple administrative endpoints and to bypass client-side validation and access sensitive system information.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2019-25234

    Last Modified: 15 Apr 2026

    SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious scripts into various application parameters.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2019-25233

    Last Modified: 28 Jul 2026

    AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to exploit login.php parameters and execute arbitrary scripts in user browser sessions.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2018-25156

    Last Modified: 5 Mar 2026

    Teradek Cube 7.3.6 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page with a hidden form to submit password change requests to the device's system configuration interface.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2018-25155

    Last Modified: 5 Mar 2026

    Teradek Slice 7.3.15 contains a cross-site request forgery vulnerability that allows attackers to change administrative passwords without proper request validation. Attackers can craft a malicious web page that automatically submits password change requests to the device when a logged-in user visits the page.

    Published: 24 Dec 2025
    8.5
    High

    CVE-2018-25154

    Last Modified: 15 Apr 2026

    GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.

    Published: 24 Dec 2025
    Unknown

    CVE-2018-25153

    Last Modified: 5 Jan 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the reported issue does not constitute a security vulnerability and represents a minor, non-exploitable memory leak.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2018-25152

    Last Modified: 15 Apr 2026

    Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a form that submits requests to the /cgi-bin/pl_web.cgi/util_configlogin_act endpoint to add superuser accounts with arbitrary credentials.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2018-25151

    Last Modified: 15 Apr 2026

    Ecessa WANWorx WVR-30 versions before 10.7.4 contain a cross-site request forgery vulnerability that allows attackers to perform administrative actions without request validation. Attackers can craft a malicious web page with a hidden form to create a new superuser account by tricking an authenticated administrator into loading the page.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2018-25150

    Last Modified: 15 Apr 2026

    Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious web page with a hidden form to add a superuser account by tricking a logged-in administrator into loading the page.

    Published: 24 Dec 2025
    5.1
    Medium

    CVE-2018-25149

    Last Modified: 26 Jan 2026

    Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change admin passwords, add new users, and modify system settings by tricking authenticated users into loading a specially crafted page.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2018-25148

    Last Modified: 21 Jan 2026

    Microhard Systems IPn4G 1.1.0 contains multiple authenticated remote code execution vulnerabilities in the admin interface that allow attackers to create crontab jobs and modify system startup scripts. Attackers can exploit hidden admin features to execute arbitrary commands with root privileges, including starting services, disabling firewalls, and writing files to the system.

    Published: 24 Dec 2025
    9.3
    Critical

    CVE-2018-25147

    Last Modified: 28 Jul 2026

    Microhard Systems IPn4G 1.1.0 contains hardcoded default credentials that cannot be changed through normal gateway operations. Attackers can exploit these default credentials to gain unauthorized root-level access to the device by logging in with predefined username and password combinations.

    Published: 24 Dec 2025
    7.1
    High

    CVE-2018-25146

    Last Modified: 2 Feb 2026

    Microhard Systems IPn4G 1.1.0 contains an undocumented vulnerability that allows authenticated attackers to list and manipulate running system processes. Attackers can send arbitrary signals to kill background processes and system services through a hidden feature, potentially causing service disruption and requiring device restart.

    Published: 24 Dec 2025
    7.1
    High

    CVE-2018-25145

    Last Modified: 28 Jul 2026

    Microhard Systems IPn4G 1.1.0 contains a configuration file disclosure vulnerability that allows authenticated attackers to download sensitive system configuration files. Attackers can retrieve configuration files from multiple directories including '/www', '/etc/m_cli/', and '/tmp' to access system passwords and network settings.

    Published: 24 Dec 2025
    8.7
    High

    CVE-2018-25144

    Last Modified: 2 Feb 2026

    Microhard Systems IPn4G 1.1.0 contains an authentication bypass vulnerability in the hidden system-editor.sh script that allows authenticated attackers to read, modify, or delete arbitrary files. Attackers can exploit unsanitized 'path', 'savefile', 'edit', and 'delfile' parameters to perform unauthorized file system modifications through GET and POST requests.

    Published: 24 Dec 2025