Vulnerabilities
Vulnerable Software
Security Vulnerabilities
An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.
CVSS Score
7.5
EPSS Score
0.0
Published
2025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyCfg function.
CVSS Score
8.8
EPSS Score
0.001
Published
2025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.
CVSS Score
8.8
EPSS Score
0.001
Published
2025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.
CVSS Score
8.8
EPSS Score
0.001
Published
2025-05-08
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function.
CVSS Score
8.8
EPSS Score
0.001
Published
2025-05-08
CVE-2025-47729
Known exploited
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.
CVSS Score
1.9
EPSS Score
0.069
Published
2025-05-08
Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-05-08
Deserialization of Untrusted Data vulnerability in Mario Peshev WP-CRM System allows Object Injection. This issue affects WP-CRM System: from n/a through 3.4.1.
CVSS Score
7.2
EPSS Score
0.001
Published
2025-05-07
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Darren Cooney Ajax Load More allows Stored XSS. This issue affects Ajax Load More: from n/a through 7.3.1.
CVSS Score
6.5
EPSS Score
0.0
Published
2025-05-07


Contact Us

Shodan ® - All rights reserved