8.7

CVSS4.0

CVE-2025-9361 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 ipRangeBlockManageRule stack-based overflow

A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. The affected element is the function ipRangeBlockManageRule of the file /goform/ipRangeBlockManageRule. Performing manipulation of the argument ipRangeBโ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 12:02 p.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 6:18 p.m.

8.7

CVSS4.0

CVE-2025-9360 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 accessControlAdd stack-based overflow

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. Impacted is the function accessControlAdd of the file /goform/accessControlAdd. Such manipulation of the argument ruleName/schedule leads โ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 10:32 a.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 6:19 p.m.

8.7

CVSS4.0

CVE-2025-9359 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_checkCredentialsByBBS stack-based overflow

A weakness has been identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function RP_checkCredentialsByBBS of the file /goform/RP_checkCredentialsByBBS. This manipulation of the argument ssidhex/pwd cโ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 9:32 a.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 6:19 p.m.

8.7

CVSS4.0

CVE-2025-9358 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setSysAdm stack-based overflow

A security flaw has been discovered in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This vulnerability affects the function setSysAdm of the file /goform/setSysAdm. The manipulation of the argument admpasshint results in stack-baโ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 7:32 a.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 6:19 p.m.

9.6

CVSS3.1

CVE-2025-5352 - Environment Variable XSS in Analytics Component in lunary-ai/lunary

A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of lunary-ai/lunary versions up to 1.9.23, where the NEXT_PUBLIC_CUSTOM_SCRIPT environment variable is directly injected into the DOM using dangerouslySetInnerHTML without any sanitization or validation. Thโ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 6:56 a.m. ๐Ÿ”„ Last Modified: Nov. 26, 2025, 5:12 p.m.

8.1

CVSS3.1

CVE-2025-5060 - Bravis User <= 1.0.1 - Authentication Bypass to Account Takeover

The Bravis User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly logging a user in with the data that was previously verified through the facebook_ajax_login_callback(). This makes it possible for unautheโ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 6:43 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 3:30 a.m.

9.8

CVSS3.1

CVE-2025-5821 - Case Theme User <= 1.0.3 - Authentication Bypass via Social Login

The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly logging in a user with the data that was previously verified through the facebook_ajax_login_callback() function. This makes it possiblโ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 6:43 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 1 a.m.

8.7

CVSS4.0

CVE-2025-9357 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 langSwitchByBBS stack-based overflow

A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This affects the function langSwitchByBBS of the file /goform/langSwitchByBBS. The manipulation of the argument langSelectionOnly leads to stack-basedโ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 6:02 a.m. ๐Ÿ”„ Last Modified: Sept. 2, 2025, 6:19 p.m.

7.2

CVSS3.1

CVE-2025-7813 - Event Manager, Events Calendar, Booking, Registrations and Tickets โ€“ Eventin <= 4.0.37 - Unauthentiโ€ฆ

The Events Calendar, Event Booking, Registrations and Event Tickets โ€“ Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to make web requests to arbโ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 5:48 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 8 p.m.

6.9

CVSS4.0

CVE-2025-43764 -

Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScript in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.1, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.20 โ€ฆ

๐Ÿ“… Published: Aug. 23, 2025, 4:49 a.m. ๐Ÿ”„ Last Modified: Dec. 12, 2025, 8:09 p.m.
Total resulsts: 349182
Page 4157 of 34,919
ยซ previous page ยป next page
Filters