9.3

CVSS4.0

CVE-2025-5408 - WAVLINK WL-WN576K1 HTTP POST Request login.cgi sys_login buffer overflow

A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical. Affected by this issue is the function sys_login of the file /cgi-bin/login.cgi of the component HTTP POST Request Handler. The manipulat…

πŸ“… Published: June 1, 2025, 9:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-5407 - chaitak-gorai Blogbook register_script.php cross site scripting

A vulnerability has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register_script.php. The manipulation of the argument fullname leads to cross site scripting…

πŸ“… Published: June 1, 2025, 9 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 8:40 p.m.

5.3

CVSS4.0

CVE-2025-5406 - chaitak-gorai Blogbook posts.php unrestricted upload

A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an unknown function of the file /admin/posts.php?source=add_post. The manipulation of the argument image leads to unrestricted upload. It is possible to…

πŸ“… Published: June 1, 2025, 6:31 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 8:43 p.m.

5.1

CVSS4.0

CVE-2025-5405 - chaitak-gorai Blogbook post.php cross site scripting

A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This issue affects some unknown processing of the file /post.php. The manipulation of the argument comment_author/comment_email/comment_content leads to cro…

πŸ“… Published: June 1, 2025, 6 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 8:04 p.m.

5.3

CVSS4.0

CVE-2025-5404 - chaitak-gorai Blogbook GET Parameter search.php denial of service

A vulnerability classified as problematic was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This vulnerability affects unknown code of the file /search.php of the component GET Parameter Handler. The manipulation of the argument Search leads to denial of service. T…

πŸ“… Published: June 1, 2025, 4:31 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 8:06 p.m.

5.3

CVSS4.0

CVE-2025-5403 - chaitak-gorai Blogbook GET Parameter view_all_posts.php sql injection

A vulnerability classified as critical has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This affects an unknown part of the file /admin/view_all_posts.php of the component GET Parameter Handler. The manipulation of the argument post_id leads to sql injection.…

πŸ“… Published: June 1, 2025, 4 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 8:07 p.m.

6.9

CVSS4.0

CVE-2025-5402 - chaitak-gorai Blogbook GET Parameter edit_post.php sql injection

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/includes/edit_post.php of the component GET Parameter Handler. The manipulation of the argument …

πŸ“… Published: June 1, 2025, 2 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 8:11 p.m.

9.1

CVSS3.1

CVE-2025-40908 - YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified

YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified

πŸ“… Published: June 1, 2025, 1:41 p.m. πŸ”„ Last Modified: July 2, 2025, 3:43 p.m.

6.9

CVSS4.0

CVE-2025-5401 - chaitak-gorai Blogbook GET Parameter post.php sql injection

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /post.php of the component GET Parameter Handler. The manipulation of the argument p_id leads …

πŸ“… Published: June 1, 2025, 1 p.m. πŸ”„ Last Modified: Nov. 10, 2025, 8:13 p.m.

6.3

CVSS3.1

CVE-2025-33005 - IBM Planning Analytics Local session fixation

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

πŸ“… Published: June 1, 2025, 11:39 a.m. πŸ”„ Last Modified: Aug. 26, 2025, 2:53 p.m.
Total resulsts: 349182
Page 5209 of 34,919
Β« previous page Β» next page
Filters