Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2025-02-13 CVE-2025-25281 Information Exposure vulnerability in Outbackpower Mojave Inverter Oghi8048A Firmware
An attacker may modify the URL to discover sensitive information about the target network.
network
low complexity
outbackpower CWE-200
7.5
2025-02-13 CVE-2025-26473 Information Exposure Through Query Strings in GET Request vulnerability in Outbackpower Mojave Inverter Oghi8048A Firmware
The Mojave Inverter uses the GET method for sensitive information.
network
low complexity
outbackpower CWE-598
7.5
2025-02-13 CVE-2025-22480 Link Following vulnerability in Dell Supportassist 3.2.0.90
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability.
local
low complexity
dell CWE-59
7.8
2025-02-13 CVE-2025-25352 SQL Injection vulnerability in PHPgurukul Land Record System 1.0
A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the pagetitle POST request parameter.
network
low complexity
phpgurukul CWE-89
7.2
2025-02-13 CVE-2025-25354 SQL Injection vulnerability in PHPgurukul Land Record System 1.0
A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter.
network
low complexity
phpgurukul CWE-89
7.2
2025-02-13 CVE-2025-25355 SQL Injection vulnerability in PHPgurukul Land Record System 1.0
A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the fromdate POST request parameter.
network
low complexity
phpgurukul CWE-89
7.2
2025-02-13 CVE-2025-25356 SQL Injection vulnerability in PHPgurukul Land Record System 1.0
A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the " todate" POST request parameter.
network
low complexity
phpgurukul CWE-89
7.2
2025-02-13 CVE-2025-25357 SQL Injection vulnerability in PHPgurukul Land Record System 1.0
A SQL Injection vulnerability was found in /admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the email POST request parameter.
network
low complexity
phpgurukul CWE-89
7.2
2025-02-13 CVE-2025-25897 Out-of-bounds Write vulnerability in Tp-Link Tl-Wr841Nd Firmware
A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV6CfgRpm.htm.
network
low complexity
tp-link CWE-787
7.5
2025-02-13 CVE-2025-25898 Out-of-bounds Write vulnerability in Tp-Link Tl-Wr841Nd Firmware
A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the pskSecret parameter at /userRpm/WlanSecurityRpm.htm.
network
low complexity
tp-link CWE-787
7.5