5.4

CVSS3.1

CVE-2025-51398 -

A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 1:30 a.m.

8.8

CVSS3.1

CVE-2025-46116 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it t…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 5:17 p.m.

6.5

CVSS3.1

CVE-2025-43720 -

Headwind MDM before 5.33.1 makes configuration details accessible to unauthorized users. The Configuration profile is exposed to the Observer user role, revealing the password requires to escape out of the MDM controlled device's profile.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 6:16 p.m.

9.8

CVSS3.1

CVE-2025-46121 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either b…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 5:18 p.m.

7.5

CVSS3.1

CVE-2025-44651 -

In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimited users are connected.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 5:56 p.m.

7.5

CVSS3.1

CVE-2025-51869 -

Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, thread_id, and message_id parameters to the v1/space/{space_id}/thread/{thread_id}/message/{message_id} endpoint.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS3.1

CVE-2025-52372 -

An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss and hMailServer.ini components.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 8, 2025, 4:19 p.m.

4.6

CVSS3.1

CVE-2025-52373 -

Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 7, 2025, 6 p.m.

9.8

CVSS3.1

CVE-2025-46120 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a rem…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 5:18 p.m.

9.1

CVSS3.1

CVE-2025-46117 -

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to…

πŸ“… Published: July 21, 2025, midnight πŸ”„ Last Modified: Aug. 5, 2025, 5:17 p.m.
Total resulsts: 349182
Page 4578 of 34,919
Β« previous page Β» next page
Filters