5.3

CVSS3.1

CVE-2025-59547 - DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has insufficient sanitization for filenames allowing probing network endpoints. A specially crafted request can be made to upload โ€ฆ

๐Ÿ“… Published: Sept. 23, 2025, 5:56 p.m. ๐Ÿ”„ Last Modified: Sept. 29, 2025, 12:57 p.m.

7

CVSS4.0

CVE-2025-52905 - TOTOLINK X6000R Argument Injection Vulnerability

Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207.

๐Ÿ“… Published: Sept. 23, 2025, 5:53 p.m. ๐Ÿ”„ Last Modified: Oct. 8, 2025, 6:06 p.m.

5.8

CVSS4.0

CVE-2025-8410 - Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulatioโ€ฆ

Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.This issue affects Connext Professional: from 7.5.0 before 7.6.0.

๐Ÿ“… Published: Sept. 23, 2025, 5:52 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 4:14 p.m.

8.3

CVSS4.0

CVE-2025-4993 - Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Poiโ€ฆ

Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.10, from 6.1.0 before 6.1.2.27, from 6.0.0 before 6.0.1.43, from 5.3.0 before 5.3.*, from 4.โ€ฆ

๐Ÿ“… Published: Sept. 23, 2025, 5:51 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:16 a.m.

4.8

CVSS4.0

CVE-2025-4582 - Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allowโ€ฆ

Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6.1.0 before 6.1.2.26, from 6.0.0 before 6.0.1.43, from 5.3.0 beโ€ฆ

๐Ÿ“… Published: Sept. 23, 2025, 5:51 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:16 a.m.

8.3

CVSS4.0

CVE-2025-1255 - Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Poiโ€ฆ

Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.2.0 before 7.3.0.9.

๐Ÿ“… Published: Sept. 23, 2025, 5:50 p.m. ๐Ÿ”„ Last Modified: Dec. 16, 2025, 4:14 p.m.

6.5

CVSS3.1

CVE-2025-59821 - DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, DNNโ€™s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that is returned to the browser. In these casesโ€ฆ

๐Ÿ“… Published: Sept. 23, 2025, 5:42 p.m. ๐Ÿ”„ Last Modified: Sept. 29, 2025, 12:58 p.m.

2.4

CVSS3.1

CVE-2025-59546 - DNN Vulnerable to Stored XSS Using Backend Admin Credentials

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include javascript which could be used for XSS based attacks. This issue has been patcheโ€ฆ

๐Ÿ“… Published: Sept. 23, 2025, 5:41 p.m. ๐Ÿ”„ Last Modified: Sept. 29, 2025, 12:56 p.m.

9.1

CVSS3.1

CVE-2025-59545 - DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed thโ€ฆ

๐Ÿ“… Published: Sept. 23, 2025, 5:41 p.m. ๐Ÿ”„ Last Modified: Sept. 29, 2025, 12:56 p.m.

6.3

CVSS3.1

CVE-2025-59539 - DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, when embedding information in the Biography field, even if that field is not rich-text, users could inject javascript code that would run in the context of the websโ€ฆ

๐Ÿ“… Published: Sept. 23, 2025, 5:41 p.m. ๐Ÿ”„ Last Modified: Sept. 29, 2025, 12:42 p.m.
Total resulsts: 349182
Page 3705 of 34,919
ยซ previous page ยป next page
Filters