5.4

CVSS3.1

CVE-2025-28096 -

OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 2 p.m.

9.8

CVSS3.1

CVE-2024-38985 -

janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 4:39 p.m.

9.8

CVSS3.1

CVE-2025-28256 -

An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /lib/cste_modules/wireless.so.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 14, 2025, 5:06 p.m.

7.5

CVSS3.1

CVE-2025-28220 -

Tenda W6_S v1.0.0.4_510 has a Buffer Overflow vulnerability in the setcfm function, which allows remote attackers to cause web server crash via parameter funcpara1 passed to the binary through a POST request.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: May 6, 2025, 6:46 p.m.

5.5

CVSS3.1

CVE-2025-28097 -

OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 1:59 p.m.

9.8

CVSS3.1

CVE-2025-25579 -

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 2:23 p.m.

5.5

CVSS3.1

CVE-2024-58128 -

In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus attackers with admin privileges can conduct XSS attacks via a global menu link.

πŸ“… Published: March 28, 2025, midnight πŸ”„ Last Modified: July 8, 2025, 5:31 p.m.

6.5

CVSS3.1

CVE-2025-31092 - WordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.4 - Cross Site Script…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affects Click to Chat – WP Support All-in-One Floating Widget: from n/a through <= 2.3.4.

πŸ“… Published: March 27, 2025, 11:21 p.m. πŸ”„ Last Modified: April 23, 2026, 3:27 p.m.

4.8

CVSS4.0

CVE-2025-2878 - Kentico CMS Additional Database Installation Wizard install.aspx cross site scripting

A vulnerability was found in Kentico CMS up to 13.0.178. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /CMSInstall/install.aspx of the component Additional Database Installation Wizard. The manipulation of the argument new database leads…

πŸ“… Published: March 27, 2025, 11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-31101 - WordPress VaultRE Contact Form 7 plugin <= 1.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vault Group Pty Ltd VaultRE Contact Form 7 allows Stored XSS.This issue affects VaultRE Contact Form 7: from n/a through 1.0.

πŸ“… Published: March 27, 2025, 10:25 p.m. πŸ”„ Last Modified: April 28, 2026, 7:30 p.m.
Total resulsts: 349182
Page 6159 of 34,919
Β« previous page Β» next page
Filters