Aggregator
CVE-2025-14655 | Tenda AC20 16.03.08.12 httpd SetSysAutoRebbotCfg formSetRebootTimer rebootTime stack-based overflow
59 minutes 52 seconds ago
A vulnerability identified as critical has been detected in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd. Performing manipulation of the argument rebootTime results in stack-based buffer overflow.
This vulnerability is reported as CVE-2025-14655. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
CVE-2025-14656 | Tenda AC20 16.03.08.12 /goform/openSchedWifi httpd schedStartTime/schedEndTime buffer overflow
59 minutes 52 seconds ago
A vulnerability labeled as critical has been found in Tenda AC20 16.03.08.12. This affects the function httpd of the file /goform/openSchedWifi. Executing manipulation of the argument schedStartTime/schedEndTime can lead to buffer overflow.
This vulnerability appears as CVE-2025-14656. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2023-29752 | Facemoji Emoji Keyboard 2.9.1.2 on Android improper authorization (EUVD-2023-33290)
1 hour 14 minutes ago
A vulnerability labeled as critical has been found in Facemoji Emoji Keyboard 2.9.1.2 on Android. This affects an unknown part. Executing manipulation can lead to improper authorization.
This vulnerability appears as CVE-2023-29752. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2023-29755 | Twilight 13.3 on Android SharedPreference File improper authorization (EUVD-2023-33293)
1 hour 14 minutes ago
A vulnerability marked as critical has been reported in Twilight 13.3 on Android. This vulnerability affects unknown code of the component SharedPreference File Handler. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2023-29755. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2023-29756 | Twilight 13.3 on Android SharedPreference File denial of service (EUVD-2023-33294)
1 hour 14 minutes ago
A vulnerability described as problematic has been identified in Twilight 13.3 on Android. This issue affects some unknown processing of the component SharedPreference File Handler. The manipulation results in denial of service.
This vulnerability is known as CVE-2023-29756. Attacking locally is a requirement. No exploit is available.
vuldb.com
CVE-2023-29757 | Blue Light Filter 1.5.5 on Android SharedPreference File improper authorization (EUVD-2023-33295)
1 hour 14 minutes ago
A vulnerability classified as critical has been found in Blue Light Filter 1.5.5 on Android. Impacted is an unknown function of the component SharedPreference File Handler. This manipulation causes improper authorization.
This vulnerability is handled as CVE-2023-29757. It is possible to launch the attack on the local host. There is not any exploit available.
vuldb.com
CVE-2023-29753 | Facemoji Emoji Keyboard 2.9.1.2 on Android SharedPreference File denial of service (EUVD-2023-33291)
1 hour 14 minutes ago
A vulnerability labeled as problematic has been found in Facemoji Emoji Keyboard 2.9.1.2 on Android. Impacted is an unknown function of the component SharedPreference File Handler. The manipulation results in denial of service.
This vulnerability is reported as CVE-2023-29753. The attack requires a local approach. No exploit exists.
vuldb.com
CVE-2023-29748 | Story Saver for Instragram App 1.0.6 on Android SharedPreference File denial of service (EUVD-2023-33286)
1 hour 14 minutes ago
A vulnerability was found in Story Saver for Instragram App 1.0.6 on Android and classified as problematic. Affected is an unknown function of the component SharedPreference File Handler. Executing manipulation can lead to denial of service.
This vulnerability is handled as CVE-2023-29748. It is possible to launch the attack on the local host. There is not any exploit available.
vuldb.com
CVE-2023-29751 | Yandex Navigator 6.60 on Android SharedPreference File denial of service (EUVD-2023-33289)
1 hour 14 minutes ago
A vulnerability was found in Yandex Navigator 6.60 on Android. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component SharedPreference File Handler. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2023-29751. The attack is restricted to local execution. No exploit exists.
vuldb.com
CVE-2023-29749 | Yandex Navigator 6.60 on Android SharedPreference File improper authorization (EUVD-2023-33287)
1 hour 14 minutes ago
A vulnerability identified as critical has been detected in Yandex Navigator 6.60 on Android. Affected by this issue is some unknown functionality of the component SharedPreference File Handler. Performing manipulation results in improper authorization.
This vulnerability is reported as CVE-2023-29749. The attack requires a local approach. No exploit exists.
vuldb.com
Submit #705035: open-source navigation CMS WebStack-Guns 1.0 Cross-Site Request Forgery [Duplicate]
1 hour 38 minutes ago
Submit #705035 / VDB-311659
qiushui
Submit #704657: Ugreen Ugreen NAS DH2100+ V5.3.0 Incorrect Access Control [Duplicate]
1 hour 39 minutes ago
Submit #704657 / VDB-336411
rgyue
Submit #704646: Ugreen NAS DH2100+ V5.3.0 Incorrect Access Control [Accepted]
1 hour 39 minutes ago
Submit #704646 / VDB-336411
rgyue
Submit #704246: WiseCleaner Wise Folder Hider 5.0.9.239 Denial of Service [Duplicate]
1 hour 42 minutes ago
Submit #704246 / VDB-222361
le0s1mba
Submit #711729: Mayan EDMS CMS 4.10 Open Redirect [Accepted]
1 hour 46 minutes ago
Submit #711729 / VDB-336410
luca_irinel
Submit #711713: Mayan EDMS CMS 4.10 Cross Site Scripting [Accepted]
1 hour 46 minutes ago
Submit #711713 / VDB-336409
luca_irinel
CVE-2025-14653 | itsourcecode Student Management System 1.0 /addrecord.php ID sql injection
2 hours 6 minutes ago
A vulnerability was found in itsourcecode Student Management System 1.0. It has been rated as critical. Impacted is an unknown function of the file /addrecord.php. This manipulation of the argument ID causes sql injection.
This vulnerability is registered as CVE-2025-14653. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
CVE-2025-14654 | Tenda AC20 16.03.08.12 httpd /goform/setPptpUserList formSetPPTPUserList list stack-based overflow
2 hours 6 minutes ago
A vulnerability categorized as critical has been discovered in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component httpd. Such manipulation of the argument list leads to stack-based buffer overflow.
This vulnerability is documented as CVE-2025-14654. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2025-14651 | MartialBE one-hub up to 0.14.27 docker-compose.yml SESSION_SECRET hard-coded key (Issue 872)
2 hours 15 minutes ago
A vulnerability was found in MartialBE one-hub up to 0.14.27. It has been classified as critical. This vulnerability affects unknown code of the file docker-compose.yml. The manipulation of the argument SESSION_SECRET leads to use of hard-coded cryptographic key
.
This vulnerability is listed as CVE-2025-14651. The attack may be initiated remotely. In addition, an exploit is available.
It is recommended to change the configuration settings.
The code maintainer recommends (translated from Chinese): "The default docker-compose example file is not recommended for production use. If you intend to use it in production, please carefully check and modify every configuration and environment variable yourself!"
vuldb.com