9.1
CVE-2025-28089 -
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
4.6
CVE-2025-2901 - org.jboss.hal-hal-parent: Stored Cross-Site Scripting (XSS) in JBoss EAP Management Console
This vulnerability is redundant to CVE-2025-23366 and CVE-2024-10234.
5.5
CVE-2024-58129 -
In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks against every page.
9.8
CVE-2025-28219 -
Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to execute arbitrary commands via parameter "deviceName" passed to the binary through a POST request.
4
CVE-2025-31335 - opensaml-core: Signature Forgery in OpenSAML
The OpenSAML C++ library before 3.3.1 allows forging of signed SAML messages via parameter manipulation (when using SAML bindings that rely on non-XML signatures).
5.5
CVE-2024-58128 -
In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.
9.8
CVE-2025-28087 -
Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.
6.3
CVE-2025-28093 -
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.
7.5
CVE-2024-48615 - libarchive: Null Pointer Dereference in Libarchive
Null Pointer Dereference vulnerability in libarchive 3.7.6 and earlier when running program bsdtar in function header_pax_extension at rchive_read_support_format_tar.c:1844:8.
7.5
CVE-2025-28221 -
Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the set_local_time function, which allows remote attackers to cause web server crash via parameter time passed to the binary through a POST request.