CVE Feed

    Dashboard / CVE

    9.6
    Critical

    CVE-2024-6107

    Last Modified: 27 Aug 2025

    Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the corresponding snaps.

    Published: 21 Jul 2025
    7.5
    High

    CVE-2025-1469

    Last Modified: 6 Jun 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted Identifiers. This issue affects Eyotek: before 11.03.2025.

    Published: 21 Jul 2025
    6.9
    Medium

    CVE-2025-4570

    Last Modified: 15 Apr 2026

    An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the ASUS Security Advisory for more information.

    Published: 21 Jul 2025
    7.7
    High

    CVE-2025-4569

    Last Modified: 15 Apr 2026

    An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized actor to obtain a token that could be used to communicate with certain services. Refer to the 'Security Update for for MyASUS' section on the ASUS Security Advisory for more information.

    Published: 21 Jul 2025
    8.6
    High

    CVE-2025-4049

    Last Modified: 15 Apr 2026

    Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue affects FARA: through 5.0.80.34.

    Published: 21 Jul 2025
    6.4
    Medium

    CVE-2025-7354

    Last Modified: 21 Apr 2026

    The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 21 Jul 2025
    6.1
    Medium

    CVE-2025-7369

    Last Modified: 21 Apr 2026

    The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.4.2. This is due to missing or incorrect nonce validation on the preview function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link. In combination with CVE-2025-7354, it leads to Reflected Cross-Site Scripting.

    Published: 21 Jul 2025
    6.4
    Medium

    CVE-2025-4685

    Last Modified: 22 Apr 2026

    The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTML data attributes of multiple widgets, in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 21 Jul 2025
    6.7
    Medium

    CVE-2025-0664

    Last Modified: 15 Apr 2026

    A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library. This may impair endpoint defenses and allow the attacker to achieve code execution with SYSTEM-level privileges.

    Published: 21 Jul 2025
    6.1
    Medium

    CVE-2025-7920

    Last Modified: 15 Apr 2026

    WinMatrix3 Web package developed by Simopro Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

    Published: 21 Jul 2025
    8.7
    High

    CVE-2025-7344

    Last Modified: 15 Apr 2026

    The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges to elevate their privileges to administrator level via a specific API.

    Published: 21 Jul 2025
    9.3
    Critical

    CVE-2025-7343

    Last Modified: 15 Apr 2026

    The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

    Published: 21 Jul 2025
    9.3
    Critical

    CVE-2025-7921

    Last Modified: 15 Apr 2026

    Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and potentially execute arbitrary code.

    Published: 21 Jul 2025
    8.4
    High

    CVE-2025-24938

    Last Modified: 11 Aug 2025

    The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged access (administrator) to the application has the potential execute commands on the operating system under the context of the webserver. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. Has the potential to inject command while creating a new User from User Management.

    Published: 21 Jul 2025
    9
    Critical

    CVE-2025-24937

    Last Modified: 11 Aug 2025

    File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. The web application allows arbitrary files to be included in a file that was downloadable and executable by the web server.

    Published: 21 Jul 2025
    9
    Critical

    CVE-2025-24936

    Last Modified: 11 Aug 2025

    The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the potential to execute commands on the operating system under the context of the webserver.

    Published: 21 Jul 2025
    7.1
    High

    CVE-2025-7919

    Last Modified: 15 Apr 2026

    WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

    Published: 21 Jul 2025
    9.3
    Critical

    CVE-2025-7918

    Last Modified: 15 Apr 2026

    WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

    Published: 21 Jul 2025
    8.6
    High

    CVE-2025-7917

    Last Modified: 15 Apr 2026

    WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attackers with administrator privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

    Published: 21 Jul 2025
    9.3
    Critical

    CVE-2025-7916

    Last Modified: 15 Apr 2026

    WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized contents.

    Published: 21 Jul 2025
    5.5
    Medium

    CVE-2025-7915

    Last Modified: 3 Dec 2025

    A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /mail/mailinactive.php of the component Login Page. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 21 Jul 2025
    8.7
    High

    CVE-2025-7914

    Last Modified: 23 Jul 2025

    A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is the function setparentcontrolinfo of the component httpd. The manipulation leads to buffer overflow. The attack can be launched remotely.

    Published: 21 Jul 2025
    9.8
    Critical

    CVE-2025-36846

    Last Modified: 12 Sept 2025

    An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed directly into the shell_exec() function of PHP. NOTE: this can be chained with CVE-2025-36845.

    Published: 21 Jul 2025
    9.8
    Critical

    CVE-2025-44658

    Last Modified: 7 Aug 2025

    In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading malicious scripts disguised with alternate extensions and tricking the web server into executing them as PHP, bypassing security mechanisms based on file extension filtering. This may lead to remote code execution (RCE), information disclosure, or full system compromise.

    Published: 21 Jul 2025
    8.8
    High

    CVE-2025-46116

    Last Modified: 5 Aug 2025

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the restricted shell and obtain a root shell on the controller.

    Published: 21 Jul 2025
    9.8
    Critical

    CVE-2025-46121

    Last Modified: 5 Aug 2025

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted request to the authenticated endpoint `/admin/_conf.jsp`, or without authentication and without direct network access to the controller by spoofing the MAC address of a favourite station and embedding malicious format specifiers in the DHCP hostname field, resulting in unauthenticated format-string processing and arbitrary code execution on the controller.

    Published: 21 Jul 2025
    5.4
    Medium

    CVE-2025-51398

    Last Modified: 7 Aug 2025

    A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

    Published: 21 Jul 2025
    4.6
    Medium

    CVE-2025-52374

    Last Modified: 7 Aug 2025

    Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other hMailServer admin consoles with configured connections.

    Published: 21 Jul 2025
    9.8
    Critical

    CVE-2020-26799

    Last Modified: 15 Apr 2026

    A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data.

    Published: 21 Jul 2025
    6.1
    Medium

    CVE-2024-55040

    Last Modified: 7 Aug 2025

    Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters.

    Published: 21 Jul 2025
    9.1
    Critical

    CVE-2025-52362

    Last Modified: 15 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validation for the _proxurl parameter can be bypassed, allowing a remote, unauthenticated attacker to submit a specially crafted URL

    Published: 21 Jul 2025
    8.6
    High

    CVE-2025-36845

    Last Modified: 12 Sept 2025

    An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). The endpoint takes a URL as input, sends a request to this address, and reflects the content in the response. This can be used to request endpoints only reachable by the application server.

    Published: 21 Jul 2025
    6.5
    Medium

    CVE-2025-43720

    Last Modified: 7 Aug 2025

    Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.

    Published: 21 Jul 2025
    5.5
    Medium

    CVE-2025-43976

    Last Modified: 7 Aug 2025

    The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.enflick.android.TextNow.activities.DialerActivity component.

    Published: 21 Jul 2025
    5.5
    Medium

    CVE-2025-43977

    Last Modified: 7 Aug 2025

    The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.skt.prod.dialer.activities.outgoingcall.OutgoingCallInternalBroadcaster component.

    Published: 21 Jul 2025
    3.9
    Low

    CVE-2025-44657

    Last Modified: 7 Aug 2025

    In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

    Published: 21 Jul 2025
    7.3
    High

    CVE-2025-44647

    Last Modified: 7 Aug 2025

    In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1 Aggressive Mode with Pre-Shared Keys to conduct offline attacks on the openly transmitted hash of the PSK.

    Published: 21 Jul 2025
    7.5
    High

    CVE-2025-44649

    Last Modified: 7 Aug 2025

    In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security parameters.

    Published: 21 Jul 2025
    7.5
    High

    CVE-2025-44652

    Last Modified: 2 Jan 2026

    In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks when unlimited users are connected.

    Published: 21 Jul 2025
    9.8
    Critical

    CVE-2025-44654

    Last Modified: 2 Jan 2026

    In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

    Published: 21 Jul 2025
    7.5
    High

    CVE-2025-44650

    Last Modified: 7 Aug 2025

    In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are connected.

    Published: 21 Jul 2025
    7.5
    High

    CVE-2025-44651

    Last Modified: 7 Aug 2025

    In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimited users are connected.

    Published: 21 Jul 2025
    7.5
    High

    CVE-2025-44653

    Last Modified: 7 Aug 2025

    In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS attacks when unlimited users are connected.

    Published: 21 Jul 2025
    9.8
    Critical

    CVE-2025-44655

    Last Modified: 7 Aug 2025

    In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for internal network attacks.

    Published: 21 Jul 2025
    9.1
    Critical

    CVE-2025-46117

    Last Modified: 5 Aug 2025

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary commands as root on the controller or specified target.

    Published: 21 Jul 2025
    5.3
    Medium

    CVE-2025-46118

    Last Modified: 5 Aug 2025

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable firmware directories and thereby expose sensitive information or compromise the controller.

    Published: 21 Jul 2025
    6.3
    Medium

    CVE-2025-46119

    Last Modified: 5 Aug 2025

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same obfuscation method persists in configuration prior to 200.18.7.1.302, allowing anyone who obtains the system configuration to recover the plaintext credentials.

    Published: 21 Jul 2025
    9.8
    Critical

    CVE-2025-46120

    Last Modified: 5 Aug 2025

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated attacker who can upload a template (e.g., via FTP) to escalate privileges and run arbitrary template code on the controller.

    Published: 21 Jul 2025
    9.1
    Critical

    CVE-2025-46122

    Last Modified: 5 Aug 2025

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute arbitrary commands as root.

    Published: 21 Jul 2025
    7.2
    High

    CVE-2025-46123

    Last Modified: 5 Aug 2025

    An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format string; a crafted password therefore triggers uncontrolled format-string processing and enables remote code execution on the controller.

    Published: 21 Jul 2025