CVE-2025-5146 – Netcore Routerd HTTP Header Handler Command Injection Vulnerability

A vulnerability has been found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2 and NBR200V2 up to 20250508 and classified as critical. This vulnerability affects the function passwd_set of the file /usr/bin/routerd of the component HTTP Header Handler. The manipulation of the argument pwd leads to command injection. The attack can be initiated remotely. The […]

CVE-2025-5145 – Netcore Query String Handler Remote Command Injection Vulnerability

A vulnerability, which was classified as critical, was found in Netcore NBR1005GPEV2, B6V2, COVER5, NAP830, NAP930, NBR100V2, NBR200V2 and POWER13 up to 20250508. This affects an unknown part of the file /www/cgi-bin/ of the component Query String Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit has […]

CVE-2025-5140 – Seeyon Zhiyuan OA Web Application System Server-Side Request Forgery Vulnerability

The following table lists the changes that have been made to the CVE-2025-5140 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 25, 2025 Action […]

CVE-2025-5139 – Qualitor Office365 File Command Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-5139 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 25, 2025 Action […]

CVE-2025-5138 – Bitwarden PDF File Handler Cross Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-5138 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 25, 2025 Action […]

CVE-2025-5137 – DedeCMS Distant Code Injection Vulnerability

The following table lists the changes that have been made to the CVE-2025-5137 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 25, 2025 Action […]

CVE-2025-5136 – Tmall Payment Identifier Handler Insecure Randomness Remote Vulnerability

The following table lists the changes that have been made to the CVE-2025-5136 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 25, 2025 Action […]

CVE-2025-5135 – Tmall Demo Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-5135 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] May. 24, 2025 Action […]