NA - CVE-2025-44647 - In TRENDnet TEW-WLC100P 2.03b03, the...
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1...
NA - CVE-2025-44650 - In Netgear R7000 V1.3.1.64_10.1.36 and EAX80...
In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf configuration file. This can cause DoS attacks when unlimited users are...
NA - CVE-2025-44651 - In TRENDnet TPL-430AP FW1.0, the...
In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimited users are connected.
NA - CVE-2025-44655 - In TOTOLink A7100RU V7.4, A950RG V5.9, and T10...
In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized access to system files, privilege escalation, or use...
NA - CVE-2025-44657 - In Linksys EA6350 V2.1.2, the chroot_local_user...
In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege...
NA - CVE-2025-44658 - In Netgear RAX30 V1.0.10.94, a PHP-FPM...
In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extensions. An attacker may exploit this by uploading...
NA - CVE-2025-52372 - An issue in hMailServer v.5.8.6 allows a local...
An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss and hMailServer.ini components.
NA - CVE-2025-52373 - Use of hardcoded cryptographic key in...
Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.
NA - CVE-2025-52374 - Use of hardcoded cryptographic key in...
Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to access other...
High - CVE-2025-7929 - A vulnerability was found in code-projects...
A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is an unknown function of the file /members/edit_Members.php. The manipulation of...