5.4

CVSS3.1

CVE-2025-45055 -

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaScript in the admin's session. This allows attacker…

πŸ“… Published: June 9, 2025, midnight πŸ”„ Last Modified: June 25, 2025, 8:24 p.m.

6.1

CVSS3.1

CVE-2025-46178 -

Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement.

πŸ“… Published: June 9, 2025, midnight πŸ”„ Last Modified: July 2, 2025, 5:50 p.m.

5.4

CVSS3.1

CVE-2025-45002 -

Vigybag v1.0 and before is vulnerable to Cross Site Scripting (XSS) via the upload profile picture function under my profile.

πŸ“… Published: June 9, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 2:15 p.m.

5.4

CVSS3.1

CVE-2025-46041 -

A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add).

πŸ“… Published: June 9, 2025, midnight πŸ”„ Last Modified: June 25, 2025, 7:39 p.m.

6.8

CVSS3.1

CVE-2025-29627 -

An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module

πŸ“… Published: June 9, 2025, midnight πŸ”„ Last Modified: July 16, 2025, 6:23 p.m.

6.1

CVSS3.1

CVE-2024-46452 -

A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b allows attackers to redirect victim users to a malicious site via a crafted URL.

πŸ“… Published: June 9, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-5851 - Tenda AC15 HTTP POST Request AdvSetLanip fromadvsetlanip buffer overflow

A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been rated as critical. This issue affects the function fromadvsetlanip of the file /goform/AdvSetLanip of the component HTTP POST Request Handler. The manipulation of the argument lanMask leads to buffer overflow. The attack may be …

πŸ“… Published: June 8, 2025, 11:31 p.m. πŸ”„ Last Modified: June 9, 2025, 7:04 p.m.

8.7

CVSS4.0

CVE-2025-5850 - Tenda AC15 HTTP POST Request SetLEDCf formsetschedled buffer overflow

A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been declared as critical. This vulnerability affects the function formsetschedled of the file /goform/SetLEDCf of the component HTTP POST Request Handler. The manipulation of the argument Time leads to buffer overflow. The attack ca…

πŸ“… Published: June 8, 2025, 11 p.m. πŸ”„ Last Modified: June 9, 2025, 7:04 p.m.

8.7

CVSS4.0

CVE-2025-5849 - Tenda AC15 HTTP POST Request SetRemoteWebCfg formSetSafeWanWebMan stack-based overflow

A vulnerability was found in Tenda AC15 15.03.05.19_multi. It has been classified as critical. This affects the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflo…

πŸ“… Published: June 8, 2025, 10:31 p.m. πŸ”„ Last Modified: June 9, 2025, 7:04 p.m.

8.7

CVSS4.0

CVE-2025-5848 - Tenda AC15 HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflow

A vulnerability was found in Tenda AC15 15.03.05.19_multi and classified as critical. Affected by this issue is the function formSetPPTPUserList of the file /goform/setPptpUserList of the component HTTP POST Request Handler. The manipulation of the argument list leads to buffer overflow. The attack…

πŸ“… Published: June 8, 2025, 10 p.m. πŸ”„ Last Modified: June 9, 2025, 7:04 p.m.
Total resulsts: 345122
Page 4716 of 34,513
Β« previous page Β» next page
Filters