CVE-2025-30140 – G-Net Dashcam BB GONX Domain Hijacking Vulnerability
The following table lists the changes that have been made to the CVE-2025-30140 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 18, 2025 Action […]
CVE-2024-57151 – Rainrocka Xinhu SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-57151 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 18, 2025 Action […]
CVE-2024-12563 – WordPress s2Member Pro Local File Inclusion Vulnerability
The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the ‘template’ attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. […]
CVE-2025-30142 – G-Net Dashcam BB GONX MAC Spoofing Authentication Bypass
The following table lists the changes that have been made to the CVE-2025-30142 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 18, 2025 Action […]
CVE-2025-30141 – G-Net Dashcam BB GONX Information Exposure and Video Stream Hijacking Vulnerability
The following table lists the changes that have been made to the CVE-2025-30141 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 18, 2025 Action […]
CVE-2025-30139 – G-Net Dashcam BB GONX Default Credentials Weak Wi-Fi Authentication
The following table lists the changes that have been made to the CVE-2025-30139 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 18, 2025 Action […]
CVE-2025-30138 – G-Net Dashcam BB GONX Unauthenticated Remote Code Execution and Data Exposure
An issue was discovered on G-Net Dashcam BB GONX devices. Managing Settings and Obtaining Sensitive Data and Sabotaging Car Battery can be performed by unauthorized persons. It allows unauthorized users to modify critical system settings once connected to its network. Attackers can extract sensitive car and driver information, mute dashcam alerts to prevent detection, disable […]
CVE-2025-30137 – G-Net GNET Hardcoded Credentials Vulnerability
The following table lists the changes that have been made to the CVE-2025-30137 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 18, 2025 Action […]
CVE-2025-29930 – ImpressCMS Local File Inclusion Vulnerability
imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET[‘seoOp’] parameter is manipulated to include malicious input (e.g., seoOp=php://filter/read=convert.base64-encode/resource=/var/www/html/config.php), the application could allow an attacker to read sensitive files on the server (Local File Inclusion, LFI). The $_GET[‘seoOp’] and $_GET[‘seoArg’] parameters are directly used without sanitization or validation. […]
CVE-2025-29907 – jsPDF CPU Denial of Service Vulnerability
The following table lists the changes that have been made to the CVE-2025-29907 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 18, 2025 Action […]