6.1
CVE-2025-48922 - GLightbox - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-078
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GLightbox allows Cross-Site Scripting (XSS).This issue affects GLightbox: from 0.0.0 before 1.0.16.
6.1
CVE-2025-48923 - Toc.js - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-077
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Toc.Js allows Cross-Site Scripting (XSS).This issue affects Toc.Js: from 0.0.0 before 3.2.1.
5.1
CVE-2025-6695 - LabRedesCefetRJ WeGIA Additional Categoria adicionar_categoria.php cross site scripting
A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This issue affects some unknown processing of the file /html/matPat/adicionar_categoria.php of the component Additional Categoria. The manipulation of the argument Insira a nova categoria leads to cross site scr…
5.1
CVE-2025-6694 - LabRedesCefetRJ WeGIA Adicionar Unidade adicionar_unidade.php cross site scripting
A vulnerability has been found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This vulnerability affects unknown code of the file /html/matPat/adicionar_unidade.php of the component Adicionar Unidade. The manipulation of the argument Insira a nova unidade leads to cross site scriptin…
8.5
CVE-2025-6693 - RT-Thread device.c sys_device_write memory corruption
A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_device_open/sys_device_read/sys_device_control/sys_device_init/sys_device_close/sys_device_write of the file components/drivers/core/device.c. The manipulation leads to memory corrup…
8.1
CVE-2025-5966 - Stored XSS
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
8.1
CVE-2025-5366 - Stored XSS
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.
8.7
CVE-2025-6562 - Hunt Electronic Hybrid DVR - OS Command Injection
Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary OS commands and execute them on the device.
9.8
CVE-2025-6561 - Hunt Electronic Hybrid DVR - Exposure of Sensitive System Information
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.
0
CVE-2025-3773 -
A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.