6.4

CVSS3.1

CVE-2025-5143 - TableOn โ€“ WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Sโ€ฆ

The TableOn โ€“ WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tableon_popup_iframe_button shortcode in all versions up to, and including, 1.0.4.1 due to insufficient input sanitization and output escaping on user supplied attributeโ€ฆ

๐Ÿ“… Published: June 21, 2025, 6:42 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 8:15 p.m.

5.1

CVSS4.0

CVE-2025-6401 - TOTOLINK N300RH HTTP POST Message formFilter denial of service

A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message Handler. The manipulation of the argument url leads to denial of service. The exploit has been discโ€ฆ

๐Ÿ“… Published: June 21, 2025, 6:31 a.m. ๐Ÿ”„ Last Modified: June 25, 2025, 8:14 p.m.

7.1

CVSS3.1

CVE-2025-5034 - WP File Download < 6.2.6 - Reflected XSS

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

๐Ÿ“… Published: June 21, 2025, 6 a.m. ๐Ÿ”„ Last Modified: July 2, 2025, 7 p.m.

8.7

CVSS4.0

CVE-2025-6400 - TOTOLINK N300RH HTTP POST Message formPortFw buffer overflow

A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formPortFw of the component HTTP POST Message Handler. The manipulation of the argument service_type leads to buffer overflow. The atโ€ฆ

๐Ÿ“… Published: June 21, 2025, 5:31 a.m. ๐Ÿ”„ Last Modified: June 25, 2025, 8:13 p.m.

8.7

CVSS4.0

CVE-2025-6399 - TOTOLINK X15 HTTP POST Request formIPv6Addr buffer overflow

A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to lauโ€ฆ

๐Ÿ“… Published: June 21, 2025, 3:31 a.m. ๐Ÿ”„ Last Modified: June 25, 2025, 8:13 p.m.

8.6

CVSS3.1

CVE-2025-52488 - DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has beeโ€ฆ

๐Ÿ“… Published: June 21, 2025, 2:51 a.m. ๐Ÿ”„ Last Modified: Sept. 15, 2025, 3:21 p.m.

8.8

CVSS4.0

CVE-2025-52487 - DNN.PLATFORM possibly allows bypass of IP Filters

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from โ€ฆ

๐Ÿ“… Published: June 21, 2025, 2:44 a.m. ๐Ÿ”„ Last Modified: Sept. 15, 2025, 3:30 p.m.

6.1

CVSS4.0

CVE-2025-52486 - DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinOโ€ฆ

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly sanitized by some SkinObjects. This issue has beenโ€ฆ

๐Ÿ“… Published: June 21, 2025, 2:42 a.m. ๐Ÿ”„ Last Modified: Sept. 15, 2025, 3:40 p.m.

5.1

CVSS4.0

CVE-2025-52485 - DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint which will then render in the feed. This issuโ€ฆ

๐Ÿ“… Published: June 21, 2025, 2:40 a.m. ๐Ÿ”„ Last Modified: Sept. 15, 2025, 3:41 p.m.

5.5

CVSS4.0

CVE-2025-52552 - FastGPT LastRoute Parameter on Login Page Vulnerable to Open Redirect and DOM-based XSS

FastGPT is an AI Agent building platform. Prior to version 4.9.12, the LastRoute Parameter on login page is vulnerable to open redirect and DOM-based XSS. Improper validation and lack of sanitization of this parameter allows attackers execute malicious JavaScript or redirect them to attacker-controโ€ฆ

๐Ÿ“… Published: June 21, 2025, 2:15 a.m. ๐Ÿ”„ Last Modified: Dec. 29, 2025, 7:06 p.m.
Total resulsts: 348441
Page 4852 of 34,845
ยซ previous page ยป next page
Filters