Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2025
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
CVSS Score
8.1
EPSS Score
0.002
Published
2025-05-08
Microsoft Dataverse Remote Code Execution Vulnerability
CVSS Score
8.7
EPSS Score
0.004
Published
2025-05-08
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1  could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyname function.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-05-08
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-05-08
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyaddr function.
CVSS Score
7.8
EPSS Score
0.0
Published
2025-05-08
phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript.
CVSS Score
6.1
EPSS Score
0.001
Published
2025-05-08
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.
CVSS Score
9.8
EPSS Score
0.003
Published
2025-05-08
TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.
CVSS Score
9.8
EPSS Score
0.003
Published
2025-05-08
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so.
CVSS Score
9.8
EPSS Score
0.003
Published
2025-05-08
TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the NoticeUrl parameter in the setNoticeCfg interface of /lib/cste_modules/system.so.
CVSS Score
9.8
EPSS Score
0.004
Published
2025-05-08


Contact Us

Shodan ® - All rights reserved