4.6
CVE-2025-54859 -
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a userβs web browser.
4.8
CVE-2025-54760 -
Stored cross-site scripting (XSS) vulnerability in desknet's NEO V9.0R2.0 and earlier allow execution of arbitrary JavaScript in a userβs web browser.
5.1
CVE-2025-52583 -
Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a userβs web browser.
4.8
CVE-2025-24833 -
Stored cross-site scripting (XSS) vulnerability in desknet's NEO versions V4.0R1.0βV9.0R2.0 allow execution of arbitrary JavaScript in a userβs web browser.
9.2
CVE-2025-6338 - Possible denial of service with multiple incoming connections to a Schannel based server with a TLSβ¦
There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.
5.3
CVE-2025-58115 -
ChatLuck contains a cross-site scripting vulnerability in Guest User Sign-up. If exploited, an arbitrary script may be executed on the web browser of the user who is accessing the product.
6.9
CVE-2025-54461 -
ChatLuck contains an insufficient granularity of access control vulnerability in Invitation of Guest Users. If exploited, an uninvited guest user may register itself as a guest user.
4.8
CVE-2025-53858 -
ChatLuck contains a cross-site scripting vulnerability in Chat Rooms. If exploited, an arbitrary script may be executed on the web browser of the user who is accessing the product.
8.1
CVE-2025-58073 - Arbitrary Mattermost Team can be joined by manipulating the OAuth state
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state.
7.5
CVE-2025-61581 - Apache Traffic Control: ReDoS issue in Traffic Router configuration
** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. People with access to the management interface of the Traffic Router component could specify malicious patterns and cause unaβ¦