5.4
CVE-2025-28096 -
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
9.8
CVE-2024-38985 -
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
9.8
CVE-2025-28256 -
An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.
7.5
CVE-2025-28220 -
Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash via parameter funcpara1 passed to the binary through a POST request.
5.5
CVE-2025-28097 -
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
9.8
CVE-2025-25579 -
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
5.5
CVE-2024-58128 -
In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.
6.5
CVE-2025-31092 - WordPress Click to Chat β WP Support All-in-One Floating Widget plugin <= 2.3.4 - Cross Site Scriptβ¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat β WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat β WP Support All-in-One Floating Widget: from n/a through <= 2.3.4.
4.8
CVE-2025-2878 - Kentico CMS Additional Database Installation Wizard install.aspx cross site scripting
A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /CMSInstall/install.aspx of the component Additional Database Installation Wizard. The manipulation of the argument new database leadsβ¦
5.9
CVE-2025-31101 - WordPress VaultRE Contact Form 7 plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vault Group Pty Ltd VaultRE Contact Form 7 allows Stored XSS.This issue affects VaultRE Contact Form 7: from n/a through 1.0.