A vulnerability was found in UTT 进取 750W up to 5.0. It has been classified as critical. This affects the function strcpy of the file /goform/setSysAdm of the component API. The manipulation of the argument passwd1 leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-6098. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in UTT 进取 750W up to 5.0 and classified as critical. Affected by this issue is the function formDefineManagement of the file /goform/setSysAdm of the component Administrator Password Handler. The manipulation of the argument passwd1 leads to unverified password change.
This vulnerability is handled as CVE-2025-6097. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in codesiddhant Jasmin Ransomware up to 1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard.php. The manipulation of the argument Search leads to sql injection.
This vulnerability is known as CVE-2025-6096. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unknown function of the file /checklogin.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability is traded as CVE-2025-6095. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, has been found in FoxCMS up to 1.2.5. This issue affects the function batchCope of the file app/admin/controller/Download.php. The manipulation of the argument ids leads to sql injection.
The identification of this vulnerability is CVE-2025-6094. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability classified as critical was found in uYanki board-stm32f103rc-berial up to 84daed541609cb7b46854cc6672a275d1007e295. This vulnerability affects the function heartrate1_i2c_hal_write of the file 7.Example/hal/i2c/max30100/Manual/demo2/2/heartrate1_hal.c. The manipulation of the argument num leads to stack-based buffer overflow.
This vulnerability was named CVE-2025-6093. Access to the local network is required for this attack. There is no exploit available.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
A vulnerability classified as critical has been found in Apache NuttX RTOS up to 12.8.x. This affects an unknown part of the component xmlrpc. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-47869. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Apache NuttX RTOS up to 12.8.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the component bdf-converter. The manipulation leads to infinite loop.
This vulnerability is handled as CVE-2025-47868. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Acid Stats 2.3. It has been declared as critical. This vulnerability affects unknown code of the file install.php3 of the component Installation. The manipulation of the argument repertoire leads to file inclusion.
This vulnerability was named CVE-2006-5899. The attack can be initiated remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
A vulnerability was found in HomeSeer HomeSeer HS2 2.5.0.20. It has been declared as critical. This vulnerability affects unknown code of the file ctrl. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2011-4837. The attack can be initiated remotely. Furthermore, there is an exploit available.