5.1
CVE-2025-43737 -
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8 and 2025.Q1.0 through 2025.Q1.15 allows a remote authenticated user to inject JavaScript code via _com_liferay_journal_web_portlet_JournalPortlet_backURL parameter.
4.9
CVE-2025-31988 - HCL Digital Experience is susceptible to cross site scripting (XSS)
HCL Digital Experience is susceptible to cross site scripting (XSS) in an administrative UI with restricted access.
6.9
CVE-2025-55303 - Unauthorized third-party images in Astroโs _image endpoint
Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served. On-demand rendered sites built with Astro include an โฆ
5.3
CVE-2025-9151 - LiuYuYang01 ThriveX-Blog web updateJsonValueByName improper authorization
A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the function updateJsonValueByName of the file /web_config/json/name/web. Performing manipulation results in improper authorization. It is possible to initiate the attack remotely. The expโฆ
8.2
CVE-2025-8450 - Unrestricted File Upload in FileCatalyst
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.
6.5
CVE-2025-55295 - qBit Manage Path Traversal Vulnerability
qBit Manage is a tool that helps manage tedious tasks in qBittorrent and automate them. A path traversal vulnerability exists in qbit_manage's web API that allows authenticated users to read arbitrary files from the server filesystem through the restore_config_from_backup endpoint. The vulnerabilitโฆ
9.8
CVE-2025-55294 - Command Injection via `format` option in screenshot-desktop
screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command without sanitization. This results in arbitrary coโฆ
6.9
CVE-2025-9150 - Surbowl dormitory-management-php violation_add.php sql injection
A vulnerability was identified in Surbowl dormitory-management-php up to 9f1d9d1f528cabffc66fda3652c56ff327fda317. Affected is an unknown function of the file /admin/violation_add.php?id=2. Such manipulation of the argument ID leads to sql injection. The attack may be performed from a remote locatiโฆ
5.3
CVE-2025-9149 - Wavlink WL-NU516U1 wireless.cgi sub_4032E4 command injection
A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cgi-bin/wireless.cgi. This manipulation of the argument Guest_ssid causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosโฆ
5.3
CVE-2025-54881 - Mermaid improperly sanitizes of sequence diagram labels leading to XSS
Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML duringโฆ