5.4

CVSS3.1

CVE-2025-5035 - Firelight Lightbox < 2.3.16 - Contributor+ Stored XSS

The Firelight Lightbox WordPress plugin before 2.3.16 does not sanitise and escape title attributes before outputting them in the page, which could allow users with a role as low as contributors to perform stored Cross-Site Scripting attacks.

πŸ“… Published: June 27, 2025, 6 a.m. πŸ”„ Last Modified: July 1, 2025, 5:43 p.m.

6.9

CVSS4.0

CVE-2025-41418 -

Buffer Overflow vulnerability exists in multiple versions of TB-eye network recorders and AHD recorders. The CGI process may be terminated abnormally by processing a specially crafted request.

πŸ“… Published: June 27, 2025, 5:24 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2025-36529 -

An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who is logging in to the device.

πŸ“… Published: June 27, 2025, 5:23 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-6488 - isMobile <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via device Parameter

The isMobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜device’ parameter in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abo…

πŸ“… Published: June 27, 2025, 4:25 a.m. πŸ”„ Last Modified: April 22, 2026, 1:15 a.m.

5.3

CVSS4.0

CVE-2025-6753 - huija bicycleSharingServer AdminController.java selectAdminByNameLike sql injection

A vulnerability was found in huija bicycleSharingServer 1.0 and classified as critical. This issue affects the function selectAdminByNameLike of the file AdminController.java. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…

πŸ“… Published: June 27, 2025, 4 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-6752 - Linksys WRT1900ACS/EA7200/EA7450/EA7500 IGD Layer3Forwarding SetDefaultConnectionService stack-base…

A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7450 and EA7500 up to 20250619 and classified as critical. This vulnerability affects the function SetDefaultConnectionService of the file /upnp/control/Layer3Forwarding of the component IGD. The manipulation of the argument NewDefault…

πŸ“… Published: June 27, 2025, 3:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-6751 - Linksys E8450 HTTP POST Request portal.cgi set_device_language buffer overflow

A vulnerability, which was classified as critical, was found in Linksys E8450 up to 1.2.00.360516. This affects the function set_device_language of the file portal.cgi of the component HTTP POST Request Handler. The manipulation of the argument dut_language leads to buffer overflow. It is possible …

πŸ“… Published: June 27, 2025, 3 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-6750 - HDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflow

A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. Affected by this issue is the function H5O__mtime_new_encode of the file src/H5Omtime.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to t…

πŸ“… Published: June 27, 2025, 2:31 a.m. πŸ”„ Last Modified: July 1, 2025, 5:44 p.m.

5.3

CVSS4.0

CVE-2025-6749 - huija bicycleSharingServer AdminController.java searchAdminMessageShow sql injection

A vulnerability classified as critical was found in huija bicycleSharingServer up to 7b8a3ba48ad618604abd4797d2e7cf3b5ac7625a. Affected by this vulnerability is the function searchAdminMessageShow of the file AdminController.java. The manipulation of the argument Title leads to sql injection. The a…

πŸ“… Published: June 27, 2025, 2 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.4

CVSS4.0

CVE-2025-6748 - Bharti Airtel Thanks App files cleartext storage in a file or on disk

A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the phy…

πŸ“… Published: June 27, 2025, 1:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4870 of 34,919
Β« previous page Β» next page
Filters