5.1
CVE-2020-36889 - Kentico Xperience <= 12.0.90 Administration Interface Stored XSS
A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via error messages containing specially crafted object names. This allows malicious scripts to execute in users' browsers when administrators view error messages in the administration interโฆ
5.3
CVE-2019-25230 - Kentico Xperience <= 12.0.0 User Widget Information Disclosure
An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects through the live site widget properties dialog. Attackers can exploit this vulnerability to access unauthorized system information without proper access controls.
8.7
CVE-2019-25229 - Kentico Xperience <= 12.0.29 MVC Forms Unrestricted File Upload
An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions to upload arbitrary file types via MVC form file uploader components. Attackers can manipulate file names and upload potentially malicious files to the system, enabling unauthorizeโฆ
5.1
CVE-2019-25228 - Kentico Xperience <= 12.0.47 Virtual Context Information Disclosure
An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP Referer header when users interact with third-party domains. Sensitive virtual context information can be exposed to external domains through page builder interactions and link/imโฆ
4.1
CVE-2025-64400 - Insufficient permission checks when pre-enrolling users Summary
Control Panel provides an API for pre-registering into an enrollment and organization prior to a user's first login. The API for creating users checks that the account requesting a user creation has `edit` on the enrollment-level user directory, but is missing a separate check that the enrollment โฆ
7.1
CVE-2025-67745 - Myhoard logs backup encryption key in plain text
MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1.3.0, in some cases, myhoard logs the whole backup info, including the encryption key. Version 1.3.0 fixes the issue. As a workaround, direct logs into /dev/null.
5.3
CVE-2025-14885 - SourceCodester Client Database Management System Leads Generation user_leads.php unrestricted upload
A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the component Leads Generation Module. Executing manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publishโฆ
5.3
CVE-2025-59949 - FreshRSS has Logout CSRF that Leads to DoS via <track src>
FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to denial of service via <track src>. Version 1.27.1 patches the issue.
6.8
CVE-2025-14739 - Uninitialized Pointer Vulnerability in TP-Link WR940N and WR941ND
Access of Uninitialized Pointer vulnerability in TP-Link WR940N and WR941ND allowsย local unauthenticated attackers the ability to execute DoS attack and potentially arbitrary code execution under the context of the โrootโ user.This issue affects WR940N and WR941ND: โค WR940N v5 3.20.1 Build 20031โฆ
5.7
CVE-2025-14738 - Configuration Disclosure Vulnerability in TP-Link WA850RE
Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: โค WA850RE V2_160527, โค WA850RE V3_160922.