Search Results (312683 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-57703 2 Delta Electronics, Deltaww 2 Diaview, Diaenergie 2025-08-21 6.1 Medium
DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57702 2 Delta Electronics, Deltaww 2 Diaview, Diaenergie 2025-08-21 6.1 Medium
DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57701 2 Delta Electronics, Deltaww 2 Diaview, Diaenergie 2025-08-21 6.1 Medium
DIAEnergie - Reflected Cross-site Scripting
CVE-2025-57700 2 Delta Electronics, Deltaww 2 Diaview, Diaenergie 2025-08-21 6.1 Medium
DIAEnergie - Stored Cross-site Scripting
CVE-2025-55503 1 Tenda 2 Ac6, Ac6 Firmware 2025-08-21 7.3 High
Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.
CVE-2025-55483 1 Tenda 2 Ac6, Ac6 Firmware 2025-08-21 7.5 High
Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and deviceList.
CVE-2025-51488 1 Moonshine 1 Moonshine 2025-08-21 4.9 Medium
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.4, allowing remote attackers to store and execute arbitrary JavaScript by including a malicious HTML payload in the Name parameter when creating a new Admin.
CVE-2025-51487 1 Moonshine 1 Moonshine 2025-08-21 4.5 Medium
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing to execute arbitrary JavaScript by using "javascript:" payload, instead of the expected HTTPS protocol, in the CutCode Link parameter when creating/updating a new Article.
CVE-2025-51489 1 Moonshine 1 Moonshine 2025-08-21 4.5 Medium
A Stored Cross-Site Scripting (XSS) vulnerability exists in MoonShine version < 3.12.5, allowing remote attackers to upload a malicious SVG file when creating/updating an Article and correctly execute arbitrary JavaScript when the file link is opened.
CVE-2025-8973 2 Oretnom23, Sourcecodester 2 Cashier Queuing System, Cashier Queuing System 2025-08-21 7.3 High
A vulnerability has been found in SourceCodester Cashier Queuing System 1.0. Affected is an unknown function of the file /Actions.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-8990 2 Anisha, Code-projects 2 Online Medicine Guide, Online Medicine Guide 2025-08-21 7.3 High
A vulnerability was determined in code-projects Online Medicine Guide 1.0. Affected is an unknown function of the file /browsemdcn.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-9011 1 Phpgurukul 1 Online Shopping Portal Project 2025-08-21 7.3 High
A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown functionality of the file /shopping/signup.php. The manipulation of the argument emailid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-9012 1 Phpgurukul 1 Online Shopping Portal Project 2025-08-21 7.3 High
A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the file shopping/bill-ship-addresses.php. The manipulation of the argument billingpincode leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-55591 1 Totolink 2 A3002r, A3002r Firmware 2025-08-21 9.8 Critical
TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endpoint.
CVE-2025-55590 1 Totolink 2 A3002r, A3002r Firmware 2025-08-21 6.5 Medium
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.
CVE-2025-55589 1 Totolink 2 A3002r, A3002r Firmware 2025-08-21 6.5 Medium
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and clientoff parameters at /boafrm/formMapDelDevice.
CVE-2025-55588 1 Totolink 2 A3002r, A3002r Firmware 2025-08-21 7.5 High
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-55587 1 Totolink 2 A3002r, A3002r Firmware 2025-08-21 7.5 High
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-55586 1 Totolink 2 A3002r, A3002r Firmware 2025-08-21 7.5 High
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-55585 1 Totolink 2 A3002r, A3002r Firmware 2025-08-21 6.5 Medium
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.