5.1

CVSS4.0

CVE-2025-3789 - baseweb JSite save cross site scripting

A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /a/sys/area/save. The manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclos…

πŸ“… Published: April 18, 2025, 12:31 p.m. πŸ”„ Last Modified: Oct. 15, 2025, 2:03 p.m.

6.3

CVSS3.1

CVE-2025-32790 - Dify Allows Insecure User Role Access Control for APP DSL Exporting

Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in '/export' should only allow administrator users to export DSL. A workaround for thi…

πŸ“… Published: April 18, 2025, 12:15 p.m. πŸ”„ Last Modified: June 19, 2025, 12:36 a.m.

6.3

CVSS3.1

CVE-2024-45651 - IBM Sterling Connect:Direct Web Services session fixation

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.

πŸ“… Published: April 18, 2025, 11:04 a.m. πŸ”„ Last Modified: Sept. 1, 2025, 12:41 a.m.

6.3

CVSS3.1

CVE-2024-49808 - IBM Sterling Connect:Direct Web Services improper authorization

IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.

πŸ“… Published: April 18, 2025, 11:03 a.m. πŸ”„ Last Modified: Sept. 1, 2025, 12:41 a.m.

5.1

CVSS4.0

CVE-2025-3788 - baseweb JSite save cross site scripting

A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /a/sys/user/save. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has bee…

πŸ“… Published: April 18, 2025, 10 a.m. πŸ”„ Last Modified: April 23, 2025, 5:34 p.m.

5.1

CVSS4.0

CVE-2025-3787 - PbootCMS Image server-side request forgery

A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and m…

πŸ“… Published: April 18, 2025, 9:31 a.m. πŸ”„ Last Modified: April 23, 2025, 5:52 p.m.

6.4

CVSS3.1

CVE-2025-3106 - LA-Studio Element Kit for Elementor <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scrip…

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi…

πŸ“… Published: April 18, 2025, 9:21 a.m. πŸ”„ Last Modified: April 22, 2026, 1:45 a.m.

8.7

CVSS4.0

CVE-2025-3786 - Tenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflow

A vulnerability was found in Tenda AC15 up to 15.03.05.19 and classified as critical. This issue affects the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument mac leads to buffer overflow. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: April 18, 2025, 9 a.m. πŸ”„ Last Modified: April 22, 2025, 4:35 p.m.

9.2

CVSS4.0

CVE-2025-2492 -

An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted request, potentially leading to unauthorized execution of functions. Refer to the 'ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.

πŸ“… Published: April 18, 2025, 8:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-3785 - D-Link DWR-M961 Authorization Interface formStaticDHCP stack-based overflow

A vulnerability has been found in D-Link DWR-M961 1.1.36 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formStaticDHCP of the component Authorization Interface. The manipulation of the argument Hostname leads to stack-based buffer overflow. The attack can be…

πŸ“… Published: April 18, 2025, 8:31 a.m. πŸ”„ Last Modified: July 16, 2025, 3:31 p.m.
Total resulsts: 349182
Page 5720 of 34,919
Β« previous page Β» next page
Filters