Vulnerabilities (CVE)

Total 398160 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-28230 1 Jmbroadcast 2 Jmb0150, Jmb0150 Firmware 2026-06-17 N/A 9.1 CRITICAL
Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.
CVE-2025-28229 1 Orban 2 Optimod 5950, Optimod 5950 Firmware 2026-06-17 N/A 9.8 CRITICAL
Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain Administrator privileges.
CVE-2025-28228 1 Electrolink 1 Fm\/dab\/tv Transmitter Web Management System 2026-06-17 N/A 7.5 HIGH
A credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4, v1.2 allows unauthorized attackers to access credentials in plaintext.
CVE-2025-28221 1 Tenda 2 W6-s, W6-s Firmware 2026-06-17 N/A 7.5 HIGH
Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the set_local_time function, which allows remote attackers to cause web server crash via parameter time passed to the binary through a POST request.
CVE-2025-28220 1 Tenda 2 W6-s, W6-s Firmware 2026-06-17 N/A 7.5 HIGH
Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash via parameter funcpara1 passed to the binary through a POST request.
CVE-2025-28219 1 Netgear 2 Dc112a, Dc112a Firmware 2026-06-17 N/A 9.8 CRITICAL
Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.
CVE-2025-28203 1 Govicture 2 Rx1800, Rx1800 Firmware 2026-06-17 N/A 8.8 HIGH
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
CVE-2025-28202 1 Govicture 2 Rx1800, Rx1800 Firmware 2026-06-17 N/A 8.8 HIGH
Incorrect access control in Victure RX1800 EN_V1.0.0_r12_110933 allows attackers to enable SSH and Telnet services without authentication.
CVE-2025-28201 1 Govicture 2 Rx1800, Rx1800 Firmware 2026-06-17 N/A 6.8 MEDIUM
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute arbitrary code or gain root access.
CVE-2025-28198 1 Hitstiresoftware 1 Hitout Car Sale 2026-06-17 N/A 5.9 MEDIUM
A SQL injection vulnerability in Hitout car sale 1.0 allows a remote attacker to obtain sensitive information via the orderBy parameter of the StoreController.java component.
CVE-2025-28197 1 Kidocode 1 Crawl4ai 2026-06-17 N/A 9.1 CRITICAL
Crawl4AI <=0.4.247 is vulnerable to SSRF in /crawl4ai/async_dispatcher.py.
CVE-2025-28169 2026-06-17 N/A 8.1 HIGH
BYD QIN PLUS DM-i Dilink OS v3.0_13.1.7.2204050.1 to v3.0_13.1.7.2312290.1_0 was discovered to cend broadcasts to the manufacturer's cloud server unencrypted, allowing attackers to execute a man-in-the-middle attack.
CVE-2025-28168 1 Multiple File Upload Project 1 Multiple File Upload 2026-06-17 N/A 6.4 MEDIUM
The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload arbitrary files. NOTE: this is a third-party component that is not supplied or supported by OutSystems.
CVE-2025-28164 1 Libpng 1 Libpng 2026-06-17 N/A 5.5 MEDIUM
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.
CVE-2025-28162 1 Libpng 1 Libpng 2026-06-17 N/A 5.5 MEDIUM
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive
CVE-2025-28146 1 Edimax 2 Br-6478ac V3, Br-6478ac V3 Firmware 2026-06-17 N/A 9.8 CRITICAL
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url in /boafrm/formLtefotaUpgradeQuectel
CVE-2025-28145 1 Edimax 2 Br-6478ac V3, Br-6478ac V3 Firmware 2026-06-17 N/A 6.5 MEDIUM
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.
CVE-2025-28144 1 Edimax 2 Br-6478ac V3, Br-6478ac V3 Firmware 2026-06-17 N/A 6.5 MEDIUM
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin parameter in the formWsc function.
CVE-2025-28143 1 Edimax 2 Br-6478ac V3, Br-6478ac V3 Firmware 2026-06-17 N/A 6.5 MEDIUM
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.
CVE-2025-28142 1 Edimax 2 Br-6478ac V3, Br-6478ac V3 Firmware 2026-06-17 N/A 6.5 MEDIUM
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.