8.7

CVSS4.0

CVE-2025-15461 - UTT 进取 520W formTaskEdit strcpy buffer overflow

A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTaskEdit. Executing a manipulation of the argument selDateType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. …

📅 Published: Jan. 5, 2026, 6:32 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:18 a.m.

8.7

CVSS4.0

CVE-2025-15460 - UTT 进取 520W formPptpClientConfig strcpy buffer overflow

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpClientConfig. Performing a manipulation of the argument EncryptionMode results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may …

📅 Published: Jan. 5, 2026, 6:02 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:18 a.m.

3.5

CVSS3.1

CVE-2025-9543 - FlexTable Google Sheets Connector < 3.19.2 - Admin+ Stored XSS

The FlexTable WordPress plugin before 3.19.2 does not sanitise and escape the imported links from Google Sheet cells, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…

📅 Published: Jan. 5, 2026, 6 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-14124 - Team < 5.0.11 - Unauthenticated SQLi

The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

📅 Published: Jan. 5, 2026, 6 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-15459 - UTT 进取 520W formUser strcpy buffer overflow

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formUser. Such manipulation of the argument passwd1 leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and ma…

📅 Published: Jan. 5, 2026, 5:32 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:17 a.m.

6.9

CVSS4.0

CVE-2025-15458 - bg5sbk MiniCMS Article post-edit.php improper authentication

A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-edit.php of the component Article Handler. Executing a manipulation can lead to improper authentication. It is possible to launch the attack remotely. The exploit has been publicl…

📅 Published: Jan. 5, 2026, 5:02 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:17 a.m.

6.9

CVSS4.0

CVE-2025-15457 - bg5sbk MiniCMS Trash File Restore post.php improper authentication

A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/mc-admin/post.php of the component Trash File Restore Handler. Performing a manipulation results in improper authentication. It is possible to initiate the attack remotely. The ex…

📅 Published: Jan. 5, 2026, 4:32 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:16 a.m.

6.9

CVSS4.0

CVE-2025-15456 - bg5sbk MiniCMS Publish page-edit.php improper authentication

A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-admin/page-edit.php of the component Publish Page Handler. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit has been disclo…

📅 Published: Jan. 5, 2026, 4:02 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:16 a.m.

6.9

CVSS4.0

CVE-2025-15455 - bg5sbk MiniCMS File Recovery Request page.php delete_page improper authentication

A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File Recovery Request Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been pu…

📅 Published: Jan. 5, 2026, 3:32 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:16 a.m.

2.3

CVSS4.0

CVE-2025-15454 - zhanglun lettura RSS ContentRender.tsx cross site scripting

A vulnerability was detected in zhanglun lettura up to 0.1.22. This issue affects some unknown processing of the file src/components/ArticleView/ContentRender.tsx of the component RSS Handler. The manipulation results in cross site scripting. The attack can be executed remotely. This attack is char…

📅 Published: Jan. 5, 2026, 3:02 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347405
Page 2115 of 34,741
« previous page » next page
Filters