5.1

CVSS4.0

CVE-2025-34264 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via dog/{agentId}

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/dog/{agentId} endpoint. When an authenticated user adds or edits Software Watchdog process rules for an agent, the monitored process name is stored in the settings array and…

📅 Published: Dec. 5, 2025, 5:17 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-34262 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devices/name/{agent_id}

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devices/name/{agent_id} endpoint. When an authenticated user renames a device, the new_name value is stored and later rendered in device listings or detail views without pro…

📅 Published: Dec. 5, 2025, 5:16 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.

9.3

CVSS4.0

CVE-2020-36877 - ReQuest Serious Play F3 Media Server <= 7.0.3 code execution

ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands as the web server user. Attackers can upload PHP executable files via the Quick File Uploader page, resulting in remote code execution on th…

📅 Published: Dec. 5, 2025, 5:16 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-34258 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/plan

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/plan endpoint. When an authenticated user adds an area to a map entry, the name parameter is stored and later rendered in the map list without HTML sanitization. A…

📅 Published: Dec. 5, 2025, 5:16 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-34259 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicemap/building

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicemap/building endpoint. When an authenticated user creates a map entry, the name parameter is stored and later rendered in the map list UI without HTML sanitzation. An …

📅 Published: Dec. 5, 2025, 5:16 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-34261 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via devicegroups/

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/devicegroups/ endpoint. When an authenticated user creates a device group, the name and description values are stored and later rendered in device group listings without pro…

📅 Published: Dec. 5, 2025, 5:16 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-34260 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/schedule

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/schedule endpoint. When an authenticated user adds a schedule to an existing task, the schedule name is stored and later rendered in schedule listings without HTML sa…

📅 Published: Dec. 5, 2025, 5:15 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.

5.1

CVSS4.0

CVE-2025-34257 - Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/defined

Advantech WISE-DeviceOn Server versions prior to 5.4 contain a stored cross-site scripting (XSS) vulnerability in the /rmm/v1/action/defined endpoint. When an authenticated user creates a task, the defined_name value is stored and later rendered in the Overview page without HTML sanitization. An at…

📅 Published: Dec. 5, 2025, 5:15 p.m. 🔄 Last Modified: Dec. 17, 2025, 5:15 p.m.

6.3

CVSS3.1

CVE-2025-66551 - Nextcloud Tables is missing an ownership check which allows moving columns into tables of other use…

Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.

📅 Published: Dec. 5, 2025, 5:15 p.m. 🔄 Last Modified: Dec. 9, 2025, 8:09 p.m.

8.7

CVSS4.0

CVE-2020-36876 - ReQuest Serious Play F3 Media Server <= 7.0.3 Debug Log Disclosure2020

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running…

📅 Published: Dec. 5, 2025, 5:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2805 of 34,919
« previous page » next page
Filters