CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2025-33083

    Last Modified: 3 Sept 2025

    IBM Concert Software 1.0.0 through 1.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 1 Sept 2025
    5.9
    Medium

    CVE-2025-33084

    Last Modified: 3 Sept 2025

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

    Published: 1 Sept 2025
    5.9
    Medium

    CVE-2025-33099

    Last Modified: 3 Sept 2025

    IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation.

    Published: 1 Sept 2025
    5.9
    Medium

    CVE-2025-33102

    Last Modified: 3 Sept 2025

    IBM Concert Software 1.0.0 through 1.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

    Published: 1 Sept 2025
    7.4
    High

    CVE-2025-9782

    Last Modified: 4 Sept 2025

    A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of the file /boafrm/formOneKeyAccessButton. Performing manipulation of the argument submit-url results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.

    Published: 1 Sept 2025
    7.4
    High

    CVE-2025-9781

    Last Modified: 4 Sept 2025

    A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file /boafrm/formFilter. Such manipulation of the argument ip6addr leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Sept 2025
    7.4
    High

    CVE-2025-9780

    Last Modified: 4 Sept 2025

    A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this issue is the function sub_419BE0 of the file /boafrm/formIpQoS. This manipulation of the argument mac causes buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.

    Published: 1 Sept 2025
    8.6
    High

    CVE-2025-2412

    Last Modified: 6 Jun 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass. This issue affects QR Menu: from s1.05.07 before v1.05.12.

    Published: 1 Sept 2025
    8.6
    High

    CVE-2025-0610

    Last Modified: 6 Jun 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Akınsoft QR Menü allows Cross Site Request Forgery. This issue affects QR Menü: from s1.05.06 before v1.05.12.

    Published: 1 Sept 2025
    7.3
    High

    CVE-2024-12925

    Last Modified: 1 Jun 2026

    Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting. This issue affects QR Menü: from s1.05.05 before v1.05.12.

    Published: 1 Sept 2025
    6.3
    Medium

    CVE-2024-12924

    Last Modified: 1 Jun 2026

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing. This issue affects QR Menü: from s1.05.05 before v1.05.12.

    Published: 1 Sept 2025
    7.4
    High

    CVE-2025-9779

    Last Modified: 4 Sept 2025

    A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_4162DC of the file /boafrm/formFilter. The manipulation of the argument ip6addr results in buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.

    Published: 1 Sept 2025
    4.3
    Medium

    CVE-2024-12914

    Last Modified: 1 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akınsoft QR Menü allows Cross-Site Scripting (XSS). This issue affects QR Menü: from s1.05.05 before v1.05.12.

    Published: 1 Sept 2025
    0.9
    Low

    CVE-2025-9778

    Last Modified: 4 Sept 2025

    A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. The manipulation leads to hard-coded credentials. An attack has to be approached locally. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used.

    Published: 1 Sept 2025
    5.9
    Medium

    CVE-2025-36133

    Last Modified: 18 Dec 2025

    IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potentially sensitive information in log files during installation that could be read by a local user on the container.

    Published: 1 Sept 2025
    5.5
    Medium

    CVE-2025-9775

    Last Modified: 4 Sept 2025

    A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.php. The manipulation of the argument image results in unrestricted upload. The attack may be launched remotely. The exploit has been made public and could be used.

    Published: 1 Sept 2025
    2.1
    Low

    CVE-2025-9774

    Last Modified: 4 Sept 2025

    A vulnerability has been found in RemoteClinic up to 2.0. This issue affects some unknown processing of the file /patients/edit-patient.php. The manipulation of the argument Email leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Sept 2025
    2.1
    Low

    CVE-2025-9773

    Last Modified: 4 Sept 2025

    A flaw has been found in RemoteClinic up to 2.0. This vulnerability affects unknown code of the file /staff/edit.php. Executing manipulation of the argument Last Name can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used.

    Published: 1 Sept 2025
    Unknown

    CVE-2025-58418

    Last Modified: 2 Sept 2025

    Not used

    Published: 1 Sept 2025
    Unknown

    CVE-2025-58419

    Last Modified: 2 Sept 2025

    Not used

    Published: 1 Sept 2025
    Unknown

    CVE-2025-58420

    Last Modified: 2 Sept 2025

    Not used

    Published: 1 Sept 2025
    Unknown

    CVE-2025-58421

    Last Modified: 2 Sept 2025

    Not used

    Published: 1 Sept 2025
    Unknown

    CVE-2025-58414

    Last Modified: 2 Sept 2025

    Not used

    Published: 1 Sept 2025
    Unknown

    CVE-2025-58415

    Last Modified: 2 Sept 2025

    Not used

    Published: 1 Sept 2025
    Unknown

    CVE-2025-58416

    Last Modified: 2 Sept 2025

    Not used

    Published: 1 Sept 2025
    Unknown

    CVE-2025-58417

    Last Modified: 2 Sept 2025

    Not used

    Published: 1 Sept 2025
    5.5
    Medium

    CVE-2025-9772

    Last Modified: 4 Sept 2025

    A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Performing manipulation of the argument image results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 1 Sept 2025
    5.5
    Medium

    CVE-2025-9771

    Last Modified: 3 Sept 2025

    A security vulnerability has been detected in SourceCodester Eye Clinic Management System 1.0. Affected by this issue is some unknown functionality of the file /main/search_index_Diagnosis.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 1 Sept 2025
    5.5
    Medium

    CVE-2025-9770

    Last Modified: 4 Sept 2025

    A weakness has been identified in Campcodes Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ of the component Admin Dashboard Login. This manipulation of the argument Password causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.

    Published: 1 Sept 2025
    0.9
    Low

    CVE-2025-9769

    Last Modified: 4 Sept 2025

    A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipulation of the argument addr with the input `echo 12345 > poc.txt` results in command injection. An attack on the physical device is feasible. The exploit has been released to the public and may be exploited.

    Published: 1 Sept 2025
    5.3
    Medium

    CVE-2025-9768

    Last Modified: 4 Sept 2025

    A vulnerability was identified in itsourcecode Sports Management System 1.0. This impacts an unknown function of the file /Admin/mode.php. The manipulation of the argument code leads to sql injection. The attack is possible to be carried out remotely.

    Published: 1 Sept 2025
    9.8
    Critical

    CVE-2022-38696

    Last Modified: 15 Apr 2026

    In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.

    Published: 1 Sept 2025
    7.8
    High

    CVE-2022-38695

    Last Modified: 15 Apr 2026

    In BootRom, there's a possible unchecked command index. This could lead to local escalation of privilege with no additional execution privileges needed.

    Published: 1 Sept 2025
    7.8
    High

    CVE-2022-38694

    Last Modified: 15 Apr 2026

    In BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additional execution privileges needed.

    Published: 1 Sept 2025
    9.8
    Critical

    CVE-2022-38693

    Last Modified: 15 Apr 2026

    In FDL1, there is a possible missing payload size check. This could lead to memory buffer overflow without requiring additional execution privileges.

    Published: 1 Sept 2025
    9.8
    Critical

    CVE-2022-38692

    Last Modified: 15 Apr 2026

    In BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffer overflow without requiring additional execution privileges.

    Published: 1 Sept 2025
    7.8
    High

    CVE-2022-38691

    Last Modified: 15 Apr 2026

    In BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additional execution privileges needed.

    Published: 1 Sept 2025
    5.9
    Medium

    CVE-2025-58318

    Last Modified: 15 Apr 2026

    Delta Electronics DIAView has an authentication bypass vulnerability.

    Published: 1 Sept 2025
    5.5
    Medium

    CVE-2025-9767

    Last Modified: 5 Sept 2025

    A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the file /Admin/sporttype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 1 Sept 2025
    5.5
    Medium

    CVE-2025-9766

    Last Modified: 8 Sept 2025

    A vulnerability was found in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/facilitator.php. Performing manipulation of the argument code results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

    Published: 1 Sept 2025
    7.5
    High

    CVE-2025-9784

    Last Modified: 19 Aug 2026

    A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS).

    Published: 1 Sept 2025
    5.5
    Medium

    CVE-2025-9765

    Last Modified: 8 Sept 2025

    A vulnerability has been found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of the file /Admin/tournament_details.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Sept 2025
    5.5
    Medium

    CVE-2025-9764

    Last Modified: 8 Sept 2025

    A flaw has been found in itsourcecode Sports Management System 1.0. Impacted is an unknown function of the file /Admin/resultdetails.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.

    Published: 1 Sept 2025
    9.3
    Critical

    CVE-2025-54857

    Last Modified: 15 Apr 2026

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge BASIC MB-A130 Ver.1.5.8 and earlier. If exploited, a remote unauthenticated attacker may execute arbitrary OS commands with root privileges.

    Published: 1 Sept 2025
    6.7
    Medium

    CVE-2025-20707

    Last Modified: 26 Feb 2026

    In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924201; Issue ID: MSV-3820.

    Published: 1 Sept 2025
    7.8
    High

    CVE-2025-20706

    Last Modified: 26 Feb 2026

    In mbrain, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09924624; Issue ID: MSV-3826.

    Published: 1 Sept 2025
    7.8
    High

    CVE-2025-20705

    Last Modified: 26 Feb 2026

    In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09989078; Issue ID: MSV-3964.

    Published: 1 Sept 2025
    8
    High

    CVE-2025-20704

    Last Modified: 26 Feb 2026

    In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01516959; Issue ID: MSV-3502.

    Published: 1 Sept 2025
    6.5
    Medium

    CVE-2025-20703

    Last Modified: 17 Feb 2026

    In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01599794; Issue ID: MSV-3708.

    Published: 1 Sept 2025
    8.8
    High

    CVE-2025-20708

    Last Modified: 26 Feb 2026

    In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01123853; Issue ID: MSV-4131.

    Published: 1 Sept 2025