5.3

CVSS4.0

CVE-2025-2701 - AMTT Hotel Broadband Operation System port_setup.php popen os command injection

A vulnerability classified as critical was found in AMTT Hotel Broadband Operation System 1.0. This vulnerability affects the function popen of the file /manager/network/port_setup.php. The manipulation of the argument SwitchVersion/SwitchWrite/SwitchIP/SwitchIndex/SwitchState leads to os command i…

πŸ“… Published: March 24, 2025, 9 a.m. πŸ”„ Last Modified: Oct. 17, 2025, 5:11 p.m.

5.1

CVSS4.0

CVE-2025-2700 - michelson Dante Editor Insert Link cross site scripting

A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the pu…

πŸ“… Published: March 24, 2025, 8:31 a.m. πŸ”„ Last Modified: April 1, 2025, 8:47 p.m.

5.1

CVSS4.0

CVE-2025-2699 - GetmeUK ContentTools Image cross site scripting

A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation of the argument onload leads to cross site scripting. The attack may be launched remotely. The expl…

πŸ“… Published: March 24, 2025, 8 a.m. πŸ”„ Last Modified: July 22, 2025, 3:07 p.m.

5.3

CVSS4.0

CVE-2025-2690 - yiisoft Yii2 MockClass.php generate deserialization

A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been d…

πŸ“… Published: March 24, 2025, 7:31 a.m. πŸ”„ Last Modified: March 24, 2025, 5:15 p.m.

5.3

CVSS4.0

CVE-2025-2689 - yiisoft Yii2 SortableIterator.php getIterator deserialization

A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit ha…

πŸ“… Published: March 24, 2025, 7 a.m. πŸ”„ Last Modified: March 24, 2025, 5:17 p.m.

5.3

CVSS4.0

CVE-2025-2688 - TOTOLINK A3000RU Syslog Configuration File ExportSyslog.sh access control

A vulnerability classified as problematic was found in TOTOLINK A3000RU up to 5.9c.5185. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ExportSyslog.sh of the component Syslog Configuration File Handler. The manipulation leads to improper access controls. The attack…

πŸ“… Published: March 24, 2025, 6:31 a.m. πŸ”„ Last Modified: July 2, 2025, 6:03 p.m.

5.3

CVSS4.0

CVE-2025-2687 - PHPGurukul eLearning System Image index.php unrestricted upload

A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been dis…

πŸ“… Published: March 24, 2025, 6 a.m. πŸ”„ Last Modified: March 27, 2025, 6:14 p.m.

3.5

CVSS3.1

CVE-2025-1203 - Slider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…

πŸ“… Published: March 24, 2025, 6 a.m. πŸ”„ Last Modified: April 8, 2025, 1:13 p.m.

3.5

CVSS3.1

CVE-2025-1062 - Slider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS

The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.95.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example …

πŸ“… Published: March 24, 2025, 6 a.m. πŸ”„ Last Modified: April 8, 2025, 1:20 p.m.

3.5

CVSS3.1

CVE-2024-13124 - Photo Gallery by 10Web < 1.8.33 - Admin+ Stored XSS

The Photo Gallery by 10Web WordPress plugin before 1.8.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: March 24, 2025, 6 a.m. πŸ”„ Last Modified: May 13, 2025, 8:08 p.m.
Total resulsts: 343168
Page 5642 of 34,317
Β« previous page Β» next page
Filters