9.3
CVE-2024-12223 - Stored Cross-site Scripting (XSS) in Nutanix Prism Central
Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim userβs session and perform actions in their security context.
0.0
CVE-2025-9132 -
Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
5.1
CVE-2025-9193 - TOTVS Portal Meu RH Password Reset redirect
A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing manipulation of the argument redirectUrl can lead to open redirect. The attack may be performed from a remote location. The exploit has been published and mβ¦
0.0
CVE-2025-55503 -
Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.
0.0
CVE-2025-55482 -
Tenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.
0.0
CVE-2025-50902 -
Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to gain sensitive information via crafted HTTP Post message.
0.0
CVE-2025-28041 -
Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication.
0.0
CVE-2024-57157 -
Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.
0.0
CVE-2024-57152 -
Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class
0.0
CVE-2024-57154 -
Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.