5.3
CVE-2025-45156 -
Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users.
7.5
CVE-2025-50708 -
An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chat URL
8.7
CVE-2025-6185 - Leviton AcquiSuite and Energy Monitoring Hub Cross-site Scripting
Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.
6.9
CVE-2025-7765 - code-projects Online Appointment Booking System addmanagerclinic.php sql injection
A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/addmanagerclinic.php. The manipulation of the argument clinic leads to sql injection. The attack can be launched remβ¦
6.9
CVE-2025-7764 - code-projects Online Appointment Booking System deletedoctorclinic.php sql injection
A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /admin/deletedoctorclinic.php. The manipulation of the argument clinic leads to sql injection. It is possible to launch the attack remotely. The β¦
5.3
CVE-2025-7763 - thinkgem JeeSite Site Controller SiteController.java select redirect
A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the function select of the file src/main/java/com/jeesite/modules/cms/web/SiteController.java of the component Site Controller. The manipulation of the argument redirect leads to open redirβ¦
6.8
CVE-2025-7397 - CLI history displays inline passwords
A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interface (CLI) in plain text within the command history. A local authenticated user that can access sensitive information like passwords within the CLI history leading to unauthorizedβ¦
7.1
CVE-2025-6391 - JSON Web Token (JWT) Exposure in Log Files
Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
8.7
CVE-2025-7762 - D-Link DI-8100 HTTP Request menu_nat_more.asp stack-based overflow
A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some unknown processing of the file /menu_nat_more.asp of the component HTTP Request Handler. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotelβ¦
5.3
CVE-2025-7759 - thinkgem JeeSite UEditor Image Grabber ActionEnter.java server-side request forgery
A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/src/main/java/com/jeesite/common/ueditor/ActionEnter.java of the component UEditor Image Grabber. Such manipulation of the argument Source leads to server-side request fβ¦