5.3

CVSS4.0

CVE-2025-10325 - Wavlink WL-WN578W2 login.cgi sub_401BA4 command injection

A vulnerability was identified in Wavlink WL-WN578W2 221110. This impacts the function sub_401340/sub_401BA4 of the file /cgi-bin/login.cgi. Such manipulation of the argument ipaddr leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might…

📅 Published: Sept. 12, 2025, 8:02 p.m. 🔄 Last Modified: Sept. 12, 2025, 8:02 p.m.

5.1

CVSS4.0

CVE-2025-43795 -

Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the…

📅 Published: Sept. 12, 2025, 7:55 p.m. 🔄 Last Modified: Sept. 12, 2025, 8:10 p.m.

6.9

CVSS4.0

CVE-2025-10324 - Wavlink WL-WN578W2 firewall.cgi sub_401C5C command injection

A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the argument pingFrmWANFilterEnabled/blockSynFloodEnabled/blockPortScanEnabled/remoteManagementEnabled causes command injection. It is possible to initiat…

📅 Published: Sept. 12, 2025, 7:32 p.m. 🔄 Last Modified: Sept. 12, 2025, 7:32 p.m.

7.1

CVSS4.0

CVE-2025-43796 -

Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application…

📅 Published: Sept. 12, 2025, 7:12 p.m. 🔄 Last Modified: Sept. 12, 2025, 7:12 p.m.

6.9

CVSS4.0

CVE-2025-10323 - Wavlink WL-WN578W2 wizard_rep.shtml sub_409184 command injection

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command injection. The attack may be performed from remote. The exploit has been made public and could be …

📅 Published: Sept. 12, 2025, 7:02 p.m. 🔄 Last Modified: Sept. 12, 2025, 7:02 p.m.

6.9

CVSS4.0

CVE-2025-10322 - Wavlink WL-WN578W2 sysinit.html password recovery

A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument newpass/confpass leads to weak password recovery. The attack is possible to be carried out remotely. The exploit has been disclosed to…

📅 Published: Sept. 12, 2025, 6:02 p.m. 🔄 Last Modified: Sept. 12, 2025, 6:02 p.m.

9.8

CVSS3.1

CVE-2025-58434 - Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads…

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attack…

📅 Published: Sept. 12, 2025, 5:37 p.m. 🔄 Last Modified: Sept. 12, 2025, 5:38 p.m.

6.9

CVSS4.0

CVE-2025-10321 - Wavlink WL-WN578W2 live_online.shtml information disclosure

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about th…

📅 Published: Sept. 12, 2025, 5:32 p.m. 🔄 Last Modified: Sept. 12, 2025, 5:32 p.m.

2.4

CVSS4.0

CVE-2025-4234 - Cortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of Credentials

A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these cr…

📅 Published: Sept. 12, 2025, 5:18 p.m. 🔄 Last Modified: Sept. 12, 2025, 5:18 p.m.

5.8

CVSS4.0

CVE-2025-4235 - User-ID Credential Agent: Cleartext Exposure of Service Account password

An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the service account password under specific non-default configurations. This allows an unprivileged Domain User to escalate privileges by exploiting the account’s permissions. The imp…

📅 Published: Sept. 12, 2025, 5:16 p.m. 🔄 Last Modified: Sept. 12, 2025, 5:16 p.m.
Total resulsts: 309427
Page 1 of 30,943
» next page
Filters