4.8

CVSS4.0

CVE-2025-2213 - Castlenet CBW383G2N Wireless Menu wlanPrimaryNetwork.asp cross site scripting

A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been declared as problematic. This vulnerability affects unknown code of the file /wlanPrimaryNetwork.asp of the component Wireless Menu. The manipulation of the argument SSID with the input <img/src/onerror=prompt(8)> leads to…

📅 Published: March 11, 2025, 11 p.m. 🔄 Last Modified: Jan. 29, 2026, 2:54 p.m.

4.8

CVSS4.0

CVE-2025-2212 - Castlenet CBW383G2N RgSwInfo.asp cross site scripting

A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an unknown part of the file /RgSwInfo.asp. The manipulation of the argument Description with the input <img/src/onerror=prompt(8)> leads to cross site scripting. It is possible to in…

📅 Published: March 11, 2025, 10:31 p.m. 🔄 Last Modified: Jan. 29, 2026, 2:52 p.m.

8.8

CVSS3.0

CVE-2025-2233 - Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerab…

Samsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Samsung SmartThings. Authentication is not required to exploit this vulnerability. Th…

📅 Published: March 11, 2025, 10:30 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

4.8

CVSS4.0

CVE-2025-2211 - aitangbao springboot-manager add cross site scripting

A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /sysDictDetail/add. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has…

📅 Published: March 11, 2025, 10 p.m. 🔄 Last Modified: May 21, 2025, 6:04 p.m.

4.8

CVSS4.0

CVE-2025-2210 - aitangbao springboot-manager add cross site scripting

A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /sysJob/add. The manipulation of the argument name leads to cross site scripting. The attack can be launched remotely. The exploit…

📅 Published: March 11, 2025, 10 p.m. 🔄 Last Modified: May 21, 2025, 6:03 p.m.

7.7

CVSS4.0

CVE-2025-27792 - Opal vulnerable to CSRF protection bypass

Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request forgery (CSRF) were insufficient application-wide. The referrer header is checked, and if it is invalid, the server returns 403. However, the referre…

📅 Published: March 11, 2025, 9:49 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-27101 - Broken Access Control in Opal filesystem's copy functionality exposes all user data

Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, when copying any parent directory to a folder in the /temp/ directory, all files in that parent directory are copied, including files which the user should not have access to. All users of the…

📅 Published: March 11, 2025, 9:32 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-2209 - aitangbao springboot-manager add cross site scripting

A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unknown function of the file /sysDict/add. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disc…

📅 Published: March 11, 2025, 9:31 p.m. 🔄 Last Modified: May 21, 2025, 5:56 p.m.

8.8

CVSS3.1

CVE-2025-1707 - Review Schema <= 2.2.4 - Authenticated (Contributor+) Local File Inclusion via Post Meta

The Review Schema plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.4 via post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing th…

📅 Published: March 11, 2025, 9:21 p.m. 🔄 Last Modified: April 21, 2026, 10:15 p.m.

4.3

CVSS3.1

CVE-2025-28868 - WordPress ZipList Recipe plugin <= 3.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe ziplist-recipe-plugin allows Cross Site Request Forgery.This issue affects ZipList Recipe: from n/a through <= 3.1.

📅 Published: March 11, 2025, 9:01 p.m. 🔄 Last Modified: April 23, 2026, 3:26 p.m.
Total resulsts: 349182
Page 6366 of 34,919
« previous page » next page
Filters