5.1

CVSS4.0

CVE-2025-15355 - NetVision Information|ISOinsight - Reflected Cross-site Scripting

ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

📅 Published: Dec. 30, 2025, 7:33 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-15232 - Tenda M3 setAdPushInfo formSetAdPushInfo stack-based overflow

A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /goform/setAdPushInfo. The manipulation of the argument mac/terminal leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit …

📅 Published: Dec. 30, 2025, 7:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 6:15 a.m.

8.7

CVSS4.0

CVE-2025-15231 - Tenda M3 setVlanInfo formSetRemoteVlanInfo stack-based overflow

A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/setVlanInfo. Executing a manipulation of the argument ID/vlan/port can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been public…

📅 Published: Dec. 30, 2025, 7:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:17 a.m.

8.7

CVSS4.0

CVE-2025-15230 - Tenda M3 setVlanPolicyData formSetVlanPolicy heap-based overflow

A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlan_truck_port results in heap-based buffer overflow. Remote exploitation of the attack is possible. The …

📅 Published: Dec. 30, 2025, 6:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 7:17 a.m.

6.9

CVSS4.0

CVE-2025-15229 - Tenda CH22 DhcpListClient fromDhcpListClient denial of service

A vulnerability has been found in Tenda CH22 up to 1.0.0.1. Affected by this vulnerability is the function fromDhcpListClient of the file /goform/DhcpListClient. Such manipulation of the argument LISTLEN leads to denial of service. The attack may be launched remotely. The exploit has been disclosed…

📅 Published: Dec. 30, 2025, 6:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 6:14 a.m.

6.1

CVSS3.1

CVE-2025-14313 - Advance WP Query Search Filter <= 1.0.10 - Reflected XSS via taxo_ajax

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

📅 Published: Dec. 30, 2025, 6 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-14312 - Advance WP Query Search Filter <= 1.0.10 - Reflected XSS via counter

The Advance WP Query Search Filter WordPress plugin through 1.0.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

📅 Published: Dec. 30, 2025, 6 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2025-15222 - Dromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserializat…

A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSerializerTemplateForJdkUseBase64.java. Such manipulation leads to deserialization. The attack can be executed remotely. This attack is characterized by high c…

📅 Published: Dec. 30, 2025, 5:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-15221 - SohuTV CacheCloud AppDataMigrateController.java index cross site scripting

A flaw has been found in SohuTV CacheCloud up to 3.2.0. This vulnerability affects the function index of the file src/main/java/com/sohu/cache/web/controller/AppDataMigrateController.java. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has …

📅 Published: Dec. 30, 2025, 5:02 a.m. 🔄 Last Modified: Jan. 6, 2026, 9:32 p.m.

5.3

CVSS4.0

CVE-2025-15220 - SohuTV CacheCloud LoginController.java init cross site scripting

A vulnerability was detected in SohuTV CacheCloud up to 3.2.0. This affects the function init of the file src/main/java/com/sohu/cache/web/controller/LoginController.java. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be use…

📅 Published: Dec. 30, 2025, 4:32 a.m. 🔄 Last Modified: Jan. 6, 2026, 9:32 p.m.
Total resulsts: 345790
Page 2014 of 34,579
« previous page » next page
Filters