A vulnerability marked as critical has been reported in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown function of the file /admin/index.php/datafile/delfile. This manipulation of the argument filename causes path traversal.
This vulnerability is tracked as CVE-2025-14520. The attack is possible to be carried out remotely. Moreover, an exploit is present.
This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability described as critical has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The affected element is an unknown function of the file /admin/index.php/datafile/download. Such manipulation of the argument filename leads to path traversal.
This vulnerability is listed as CVE-2025-14521. The attack may be performed from remote. In addition, an exploit is available.
This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical has been found in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /Public/Kindeditor/php/upload_json.php. Performing a manipulation of the argument imgFile results in unrestricted upload.
This vulnerability is cataloged as CVE-2025-14522. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability marked as critical has been reported in TeamViewer DEX up to 28/29. Affected by this vulnerability is an unknown functionality of the component 1E-ConfigMgrConsoleExtensions. The manipulation leads to improper input validation.
This vulnerability is referenced as CVE-2025-64993. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in TeamViewer DEX up to 17.0. Impacted is an unknown function of the component 1E-Nomad-SetWorkRate. Executing a manipulation can lead to uncontrolled search path.
This vulnerability is registered as CVE-2025-64994. The attack needs to be launched locally. No exploit is available.
You should upgrade the affected component.
A vulnerability has been found in TeamViewer DEX up to 3.3 and classified as problematic. The affected element is an unknown function of the component -Exchange-NomadClientHealth-ConfigureGeneralSetting. The manipulation leads to uncontrolled search path.
This vulnerability is documented as CVE-2025-64995. The attack needs to be performed locally. There is not any exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, was found in TP-Link Tapo C210 up to 3.1.5/3.1.600 on iOS/Android. The impacted element is an unknown function of the component API. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2025-14553. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
A vulnerability was found in FastAdmin up to 1.7.0.20250506 and classified as critical. Affected is the function selectpage of the file application/common/controller/Backend.php of the component Backend Controller. Executing a manipulation of the argument custom/searchField can lead to sql injection.
This vulnerability is registered as CVE-2025-14966. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability labeled as critical has been found in TP-Link Tapo C200 V3. This impacts an unknown function of the component HTTP Header Handler. Such manipulation of the argument Content-Length leads to allocation of resources.
This vulnerability is documented as CVE-2025-14299. The attack requires being on the local network. There is not any exploit available.