8.7

CVSS4.0

CVE-2025-6402 - TOTOLINK X15 HTTP POST Request formIpv6Setup buffer overflow

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formIpv6Setup of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack ca…

πŸ“… Published: June 21, 2025, 8:31 a.m. πŸ”„ Last Modified: June 25, 2025, 8:14 p.m.

6.4

CVSS3.1

CVE-2025-5143 - TableOn – WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-S…

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tableon_popup_iframe_button shortcode in all versions up to, and including, 1.0.4.1 due to insufficient input sanitization and output escaping on user supplied attribute…

πŸ“… Published: June 21, 2025, 6:42 a.m. πŸ”„ Last Modified: April 8, 2026, 4:49 p.m.

5.1

CVSS4.0

CVE-2025-6401 - TOTOLINK N300RH HTTP POST Message formFilter denial of service

A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message Handler. The manipulation of the argument url leads to denial of service. The exploit has been disc…

πŸ“… Published: June 21, 2025, 6:31 a.m. πŸ”„ Last Modified: June 25, 2025, 8:14 p.m.

7.1

CVSS3.1

CVE-2025-5034 - WP File Download < 6.2.6 - Reflected XSS

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

πŸ“… Published: June 21, 2025, 6 a.m. πŸ”„ Last Modified: July 2, 2025, 7 p.m.

8.7

CVSS4.0

CVE-2025-6400 - TOTOLINK N300RH HTTP POST Message formPortFw buffer overflow

A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formPortFw of the component HTTP POST Message Handler. The manipulation of the argument service_type leads to buffer overflow. The at…

πŸ“… Published: June 21, 2025, 5:31 a.m. πŸ”„ Last Modified: June 25, 2025, 8:13 p.m.

8.7

CVSS4.0

CVE-2025-6399 - TOTOLINK X15 HTTP POST Request formIPv6Addr buffer overflow

A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to lau…

πŸ“… Published: June 21, 2025, 3:31 a.m. πŸ”„ Last Modified: June 25, 2025, 8:13 p.m.

8.6

CVSS3.1

CVE-2025-52488 - DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has bee…

πŸ“… Published: June 21, 2025, 2:51 a.m. πŸ”„ Last Modified: Sept. 15, 2025, 3:21 p.m.

8.8

CVSS4.0

CVE-2025-52487 - DNN.PLATFORM possibly allows bypass of IP Filters

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from …

πŸ“… Published: June 21, 2025, 2:44 a.m. πŸ”„ Last Modified: Sept. 15, 2025, 3:30 p.m.

6.1

CVSS4.0

CVE-2025-52486 - DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinO…

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly sanitized by some SkinObjects. This issue has been…

πŸ“… Published: June 21, 2025, 2:42 a.m. πŸ”„ Last Modified: Sept. 15, 2025, 3:40 p.m.

5.1

CVSS4.0

CVE-2025-52485 - DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint which will then render in the feed. This issu…

πŸ“… Published: June 21, 2025, 2:40 a.m. πŸ”„ Last Modified: Sept. 15, 2025, 3:41 p.m.
Total resulsts: 343948
Page 4403 of 34,395
Β« previous page Β» next page
Filters