5.3
CVE-2025-59547 - DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has insufficient sanitization for filenames allowing probing network endpoints. A specially crafted request can be made to upload โฆ
7
CVE-2025-52905 - TOTOLINK X6000R Argument Injection Vulnerability
Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1360_B20241207.
5.8
CVE-2025-8410 - Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulatioโฆ
Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.This issue affects Connext Professional: from 7.5.0 before 7.6.0.
8.3
CVE-2025-4993 - Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Poiโฆ
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.10, from 6.1.0 before 6.1.2.27, from 6.0.0 before 6.0.1.43, from 5.3.0 before 5.3.*, from 4.โฆ
4.8
CVE-2025-4582 - Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allowโฆ
Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation, Overread Buffers.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.0.0 before 7.3.0.8, from 6.1.0 before 6.1.2.26, from 6.0.0 before 6.0.1.43, from 5.3.0 beโฆ
8.3
CVE-2025-1255 - Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Poiโฆ
Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.This issue affects Connext Professional: from 7.4.0 before 7.6.0, from 7.2.0 before 7.3.0.9.
6.5
CVE-2025-59821 - DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, DNNโs URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that is returned to the browser. In these casesโฆ
2.4
CVE-2025-59546 - DNN Vulnerable to Stored XSS Using Backend Admin Credentials
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include javascript which could be used for XSS based attacks. This issue has been patcheโฆ
9.1
CVE-2025-59545 - DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed thโฆ
6.3
CVE-2025-59539 - DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, when embedding information in the Biography field, even if that field is not rich-text, users could inject javascript code that would run in the context of the websโฆ