NA - CVE-2025-27408 - Manifest offers users a one-file micro back...
Manifest offers users a one-file micro back end. Prior to version 4.9.1, Manifest employs a weak password hashing implementation that uses SHA3 without a salt. This exposes user passwords to a...
Critical - CVE-2025-0159 - IBM FlashSystem (IBM Storage Virtualize...
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1,...
High - CVE-2025-0160 - IBM FlashSystem (IBM Storage Virtualize...
IBM FlashSystem (IBM Storage Virtualize (8.5.0.0 through 8.5.0.13, 8.5.1.0, 8.5.2.0 through 8.5.2.3, 8.5.3.0 through 8.5.3.1, 8.5.4.0, 8.6.0.0 through 8.6.0.5, 8.6.1.0, 8.6.2.0 through 8.6.2.1,...
NA - CVE-2025-1795 - During an address list folding when a...
During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that...
NA - CVE-2025-25429 - Trendnet TEW-929DRU 1.0.0.10 contains a Stored...
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside the have_same_name function on the /addschedule.htm page.
NA - CVE-2025-25609 - TOTOlink A3002R V1.1.1-B20200824.0128 contains...
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_ipv6 parameter in the formIpv6Setup...
NA - CVE-2025-25610 - TOTOlink A3002R V1.1.1-B20200824.0128 contains...
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface...
NA - CVE-2025-25635 - TOTOlink A3002R V1.1.1-B20200824.0128 contains...
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup...
NA - CVE-2025-0769 - PixelYourSite - Your smart PIXEL (TAG) and API...
PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in...