6.9

CVSS4.0

CVE-2025-10324 - Wavlink WL-WN578W2 firewall.cgi sub_401C5C command injection

A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.cgi. This manipulation of the argument pingFrmWANFilterEnabled/blockSynFloodEnabled/blockPortScanEnabled/remoteManagementEnabled causes command injection. It is possible to initiat…

📅 Published: Sept. 12, 2025, 7:32 p.m. 🔄 Last Modified: Oct. 2, 2025, 7:45 p.m.

7.1

CVSS4.0

CVE-2025-43796 -

Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application…

📅 Published: Sept. 12, 2025, 7:12 p.m. 🔄 Last Modified: Dec. 16, 2025, 3:24 p.m.

6.9

CVSS4.0

CVE-2025-10323 - Wavlink WL-WN578W2 wizard_rep.shtml sub_409184 command injection

A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wizard_rep.shtml. The manipulation of the argument sel_EncrypTyp results in command injection. The attack may be performed from remote. The exploit has been made public and could be …

📅 Published: Sept. 12, 2025, 7:02 p.m. 🔄 Last Modified: Oct. 2, 2025, 7:47 p.m.

6.9

CVSS4.0

CVE-2025-10322 - Wavlink WL-WN578W2 sysinit.html password recovery

A vulnerability has been found in Wavlink WL-WN578W2 221110. The affected element is an unknown function of the file /sysinit.html. The manipulation of the argument newpass/confpass leads to weak password recovery. The attack is possible to be carried out remotely. The exploit has been disclosed to…

📅 Published: Sept. 12, 2025, 6:02 p.m. 🔄 Last Modified: Oct. 2, 2025, 7:54 p.m.

9.8

CVSS3.1

CVE-2025-58434 - Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads…

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attack…

📅 Published: Sept. 12, 2025, 5:37 p.m. 🔄 Last Modified: Sept. 20, 2025, 2:54 a.m.

6.9

CVSS4.0

CVE-2025-10321 - Wavlink WL-WN578W2 live_online.shtml information disclosure

A flaw has been found in Wavlink WL-WN578W2 221110. Impacted is an unknown function of the file /live_online.shtml. Executing manipulation can lead to information disclosure. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about th…

📅 Published: Sept. 12, 2025, 5:32 p.m. 🔄 Last Modified: Oct. 2, 2025, 7:56 p.m.

2.4

CVSS4.0

CVE-2025-4234 - Cortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of Credentials

A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these cr…

📅 Published: Sept. 12, 2025, 5:18 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS4.0

CVE-2025-4235 - User-ID Credential Agent: Cleartext Exposure of Service Account password

An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the service account password under specific non-default configurations. This allows an unprivileged Domain User to escalate privileges by exploiting the account’s permissions. The imp…

📅 Published: Sept. 12, 2025, 5:16 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2025-43787 -

A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20…

📅 Published: Sept. 12, 2025, 4:09 p.m. 🔄 Last Modified: Dec. 16, 2025, 3:12 p.m.

2.3

CVSS4.0

CVE-2025-10320 - iteachyou Dreamer CMS updatePwd weak password

A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in weak password requirements. Remote exploitation of the attack is possible. A high degree of complexity is needed for …

📅 Published: Sept. 12, 2025, 4:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3890 of 34,919
« previous page » next page
Filters