6.5

CVSS3.1

CVE-2024-40113 -

Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and before is vulnerable to Use of Default Credentials.

๐Ÿ“… Published: June 2, 2025, midnight ๐Ÿ”„ Last Modified: June 24, 2025, 1 a.m.

5.1

CVSS4.0

CVE-2025-5412 - Mist Community Edition Authentication Endpoint views.py login cross site scripting

A vulnerability classified as problematic has been found in Mist Community Edition up to 4.7.1. Affected is the function Login of the file src/mist/api/views.py of the component Authentication Endpoint. The manipulation of the argument return_to leads to cross site scripting. It is possible to launโ€ฆ

๐Ÿ“… Published: June 1, 2025, 11:31 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 2:49 p.m.

5.1

CVSS4.0

CVE-2025-5411 - Mist Community Edition views.py tag_resources cross site scripting

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been rated as problematic. This issue affects the function tag_resources of the file src/mist/api/tag/views.py. The manipulation of the argument tag leads to cross site scripting. The attack may be initiated remotely. The exploโ€ฆ

๐Ÿ“… Published: June 1, 2025, 11 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 2:50 p.m.

5.3

CVSS4.0

CVE-2025-5410 - Mist Community Edition middleware.py session_start_response cross-site request forgery

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been declared as problematic. This vulnerability affects the function session_start_response of the file src/mist/api/auth/middleware.py. The manipulation leads to cross-site request forgery. The attack can be initiated remotelโ€ฆ

๐Ÿ“… Published: June 1, 2025, 10:31 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 2:55 p.m.

6.9

CVSS4.0

CVE-2025-5409 - Mist Community Edition API Token views.py create_token access control

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py of the component API Token Handler. The manipulation leads to improper access controls. It is possible to initiate the aโ€ฆ

๐Ÿ“… Published: June 1, 2025, 10 p.m. ๐Ÿ”„ Last Modified: Nov. 25, 2025, 2:58 p.m.

9.3

CVSS4.0

CVE-2025-5408 - WAVLINK WL-WN576K1 HTTP POST Request login.cgi sys_login buffer overflow

A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to V1410_240222 and classified as critical. Affected by this issue is the function sys_login of the file /cgi-bin/login.cgi of the component HTTP POST Request Handler. The manipulatโ€ฆ

๐Ÿ“… Published: June 1, 2025, 9:31 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-5407 - chaitak-gorai Blogbook register_script.php cross site scripting

A vulnerability has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register_script.php. The manipulation of the argument fullname leads to cross site scriptingโ€ฆ

๐Ÿ“… Published: June 1, 2025, 9 p.m. ๐Ÿ”„ Last Modified: Nov. 10, 2025, 8:40 p.m.

5.3

CVSS4.0

CVE-2025-5406 - chaitak-gorai Blogbook posts.php unrestricted upload

A vulnerability, which was classified as critical, was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. Affected is an unknown function of the file /admin/posts.php?source=add_post. The manipulation of the argument image leads to unrestricted upload. It is possible toโ€ฆ

๐Ÿ“… Published: June 1, 2025, 6:31 p.m. ๐Ÿ”„ Last Modified: Nov. 10, 2025, 8:43 p.m.

5.1

CVSS4.0

CVE-2025-5405 - chaitak-gorai Blogbook post.php cross site scripting

A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This issue affects some unknown processing of the file /post.php. The manipulation of the argument comment_author/comment_email/comment_content leads to croโ€ฆ

๐Ÿ“… Published: June 1, 2025, 6 p.m. ๐Ÿ”„ Last Modified: Nov. 10, 2025, 8:04 p.m.

5.3

CVSS4.0

CVE-2025-5404 - chaitak-gorai Blogbook GET Parameter search.php denial of service

A vulnerability classified as problematic was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This vulnerability affects unknown code of the file /search.php of the component GET Parameter Handler. The manipulation of the argument Search leads to denial of service. Tโ€ฆ

๐Ÿ“… Published: June 1, 2025, 4:31 p.m. ๐Ÿ”„ Last Modified: Nov. 10, 2025, 8:06 p.m.
Total resulsts: 346297
Page 4920 of 34,630
ยซ previous page ยป next page
Filters