Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2025-01-15 CVE-2025-0484 Unspecified vulnerability in Fanli2012 Native-PHP-Cms 1.0
A vulnerability was found in Fanli2012 native-php-cms 1.0 and classified as critical.
network
low complexity
fanli2012
7.5
2025-01-15 CVE-2020-8094 Untrusted Search Path vulnerability in Bitdefender Antivirus 2020 1.0.15.138
An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free 2020 allows a low-privilege attacker to execute code as SYSTEM via a specially crafted DLL file.
local
low complexity
bitdefender CWE-426
7.8
2025-01-15 CVE-2024-57011 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2350B20230313
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScheduleCfg.
network
low complexity
totolink CWE-78
8.8
2025-01-15 CVE-2024-57012 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2350B20230313
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setScheduleCfg.
network
low complexity
totolink CWE-78
8.8
2025-01-15 CVE-2024-57013 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2350B20230313
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setScheduleCfg.
network
low complexity
totolink CWE-78
8.8
2025-01-15 CVE-2024-57014 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2350B20230313
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScheduleCfg.
network
low complexity
totolink CWE-78
8.8
2025-01-15 CVE-2024-57015 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2350B20230313
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setScheduleCfg.
network
low complexity
totolink CWE-78
8.8
2025-01-15 CVE-2024-57016 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2350B20230313
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAccountCfg.
network
low complexity
totolink CWE-78
8.8
2025-01-15 CVE-2024-57017 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2350B20230313
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAccountCfg.
network
low complexity
totolink CWE-78
8.8
2025-01-15 CVE-2024-57018 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0Cu.2350B20230313
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAccountCfg.
network
low complexity
totolink CWE-78
8.8