Aggregator
CVE-2025-25617 | Unifiedtransform 2.x Syllabus access control
9 months 1 week ago
A vulnerability was found in Unifiedtransform 2.x and classified as critical. Affected by this issue is some unknown functionality of the component Syllabus Handler. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2025-25617. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-27519 | truefoundry cognita Environment Variable upload-to-local-directory path traversal (GHSL-2024-193)
9 months 1 week ago
A vulnerability has been found in truefoundry cognita and classified as critical. Affected by this vulnerability is an unknown functionality of the file /v1/internal/upload-to-local-directory of the component Environment Variable Handler. The manipulation leads to path traversal.
This vulnerability is known as CVE-2025-27519. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-27518 | truefoundry cognita cross site scripting (GHSL-2024-193)
9 months 1 week ago
A vulnerability, which was classified as problematic, was found in truefoundry cognita. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-27518. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Updates on CVE for End-of-Life Versions
9 months 1 week ago
SecWiki News 2025-03-07 Review
9 months 1 week ago
Роскомнадзор требует уведомления об использовании Google Analytics
9 months 1 week ago
Ведомство усилило контроль за трансграничной передачей данных.
Tengyuan Design Allegedly Hit by Data Breach, Client & Employee Information Exposed
9 months 1 week ago
Tengyuan Design Allegedly Hit by Data Breach, Client & Employee Information Exposed
Dark Web Informer - Cyber Threat Intelligence
CVE-2025-2097 | TOTOLINK EX1800T 9.1.0cu.2112_B20220316 /cgi-bin/cstecgi.cgi setRptWizardCfg loginpass stack-based overflow
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue affects the function setRptWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument loginpass leads to stack-based buffer overflow.
The identification of this vulnerability is CVE-2025-2097. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2096 | TOTOLINK EX1800T 9.1.0cu.2112_B20220316 /cgi-bin/cstecgi.cgi setRebootScheCfg mode/week/minute/recHour os command injection
9 months 1 week ago
A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This vulnerability affects the function setRebootScheCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mode/week/minute/recHour leads to os command injection.
This vulnerability was named CVE-2025-2096. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2095 | TOTOLINK EX1800T 9.1.0cu.2112_B20220316 /cgi-bin/cstecgi.cgi setDmzCfg ip os command injection
9 months 1 week ago
A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-2095. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-2094 | TOTOLINK EX1800T 9.1.0cu.2112_B20220316 /cgi-bin/cstecgi.cgi setWiFiExtenderConfig apcliKey/key os command injection
9 months 1 week ago
A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliKey/key leads to os command injection.
This vulnerability is handled as CVE-2025-2094. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #515326: Totolink EX1800T V9.1.0cu.2112_B20220316 Stack-based Buffer Overflow [Accepted]
9 months 1 week ago
Submit #515326 / VDB-298955
selph
Submit #515325: Totolink EX1800T V9.1.0cu.2112_B20220316 OS Command Injection [Duplicate]
9 months 1 week ago
Submit #515325 / VDB-298954
selph
Submit #515324: Totolink EX1800T V9.1.0cu.2112_B20220316 OS Command Injection [Duplicate]
9 months 1 week ago
Submit #515324 / VDB-298954
selph
Submit #515323: Totolink EX1800T V9.1.0cu.2112_B20220316 OS Command Injection [Duplicate]
9 months 1 week ago
Submit #515323 / VDB-298954
selph
Submit #515322: Totolink EX1800T V9.1.0cu.2112_B20220316 OS Command Injection [Accepted]
9 months 1 week ago
Submit #515322 / VDB-298954
selph
Submit #515321: Totolink EX1800T V9.1.0cu.2112_B20220316 OS Command Injection [Accepted]
9 months 1 week ago
Submit #515321 / VDB-298953
selph
Submit #515320: Totolink EX1800T V9.1.0cu.2112_B20220316 OS Command Injection [Duplicate]
9 months 1 week ago
Submit #515320 / VDB-298952
selph
Submit #515319: Totolink EX1800T V9.1.0cu.2112_B20220316 OS Command Injection [Accepted]
9 months 1 week ago
Submit #515319 / VDB-298952
selph