7.5
CVE-2025-3091 - MB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24
An low privileged remote attacker in possession of the second factor for another user can login as that user without knowledge of the other user`s password.
8.2
CVE-2025-3090 - MB connect line: Missing Authentication in mbCONNECT24/mymbCONNECT24
An unauthenticated remote attacker can obtain limited sensitive information and/or DoS the device due to missing authentication for critical function.
6.4
CVE-2025-5258 - Conference Scheduler <= 2.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via classN…
The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
9.8
CVE-2025-50213 - Apache Airflow Providers Snowflake: Potential SQL injection in CopyFromExternalStageToSnowflakeOper…
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added in CopyFromExternalStageToSnowflake…
8.2
CVE-2025-2962 - Infinite loop in dns_copy_qname
A denial-of-service issue in the dns implemenation could cause an infinite loop.
9.3
CVE-2025-48890 -
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in miniigd SOAP service. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be execu…
9.3
CVE-2025-43879 -
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in the telnet function. If a remote unauthenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be execut…
4.8
CVE-2025-43877 -
WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be executed on the web browser of the user who accessed WebGUI of the product.
8.7
CVE-2025-41427 -
WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If a remote authenticated attacker sends a specially crafted request to the affected product, an arbitrary …
5.3
CVE-2025-36519 -
Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially crafted file is uploaded by a remote authenticated attacker, arbit…