Common Vulnerabilities and Exposures (CVE)

CVE-2025-34040

Nov 17, 2025 21:34:13 UTC

An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers t...

CVE-2025-34041

Nov 17, 2025 21:30:42 UTC

An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct a...

CVE-2025-13301

Nov 17, 2025 21:28:56 UTC

A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /subject/controller.php. The manipulation results in sql injection. It is ...

CVE-2025-34042

Nov 17, 2025 21:28:31 UTC

An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via the ServerName and TimeZone parameters in the servetest CGI page. An attacker with access to the web interface can injec...

CVE-2025-55055

Nov 17, 2025 21:24:53 UTC

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2025-55056

Nov 17, 2025 21:24:21 UTC

Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

CVE-2025-34054

Nov 17, 2025 21:23:54 UTC

An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parame...

CVE-2025-34049

Nov 17, 2025 21:23:06 UTC

An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 1127.190306 and earlier. The router’s web management interface fails to properly sanitize user input in the target_addr par...

CVE-2025-34047

Nov 17, 2025 21:22:13 UTC

A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attackers to read arbitrary files on the underlying system via the ostype parameter in the /vpn/user/download/client endpoint....

CVE-2025-55057

Nov 17, 2025 21:21:55 UTC

Multiple CWE-352 Cross-Site Request Forgery (CSRF)

CVE-2025-34046

Nov 17, 2025 21:21:13 UTC

An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with c...

CVE-2025-13297

Nov 17, 2025 21:21:04 UTC

A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impacted element is an unknown function of the file /course/controller.php. Such manipulation leads to sql injection. The at...

CVE-2025-34045

Nov 17, 2025 21:19:57 UTC

A path traversal vulnerability exists in WeiPHP 5.0, an open source WeChat public account platform development framework by Shenzhen Yuanmengyun Technology Co., Ltd. The flaw occurs in the picUrl parameter of the /public/index.php/material/...

CVE-2025-34044

Nov 17, 2025 21:15:30 UTC

A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attack...

CVE-2025-34048

Nov 17, 2025 21:12:32 UTC

A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL routers with firmware versions IN_1.02, SEA_1.04, and SEA_1.07. The vulnerability is due to insufficient input validati...