4.8

CVSS4.0

CVE-2025-5543 - TOTOLINK X2000R Parent Controls Page cross site scripting

A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Parent Controls Page. The manipulation of the argument Device Name leads to cross site scripting. The attack can be lau…

πŸ“… Published: June 3, 2025, 10:31 p.m. πŸ”„ Last Modified: June 6, 2025, 6:47 p.m.

4.8

CVSS4.0

CVE-2025-5542 - TOTOLINK X2000R Virtual Server Page formPortFw cross site scripting

A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been classified as problematic. Affected is an unknown function of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. It is possible …

πŸ“… Published: June 3, 2025, 10 p.m. πŸ”„ Last Modified: June 6, 2025, 6:47 p.m.

3.5

CVSS3.1

CVE-2025-49000 - InvenTree has uncontrolled memory allocation via built-in label-sheet plugin

InvenTree is an Open Source Inventory Management System. Prior to version 0.17.13, the skip field in the built-in `label-sheet` plugin lacks an upper bound, so a large value forces the server to allocate an enormous Python list. This lets any authenticated label-printing user trigger a denial-of-se…

πŸ“… Published: June 3, 2025, 8:54 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 3:10 p.m.

9.3

CVSS4.0

CVE-2025-48951 - Auth0-PHP SDK Deserialization of Untrusted Data vulnerability

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafte…

πŸ“… Published: June 3, 2025, 8:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.2

CVSS4.0

CVE-2025-49002 - Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v…

πŸ“… Published: June 3, 2025, 8:37 p.m. πŸ”„ Last Modified: June 5, 2025, 2:07 p.m.

7.7

CVSS4.0

CVE-2025-49001 - Dataease Authentication Bypass Vulnerability

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.10.10. No known workarounds are available.

πŸ“… Published: June 3, 2025, 8:33 p.m. πŸ”„ Last Modified: June 5, 2025, 2:07 p.m.

6.8

CVSS4.0

CVE-2025-48999 - Dataease Redshift Data Source JDBC Connection Parameters Not Verified Leads to RCE Vulnerability

DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, it will not enter the if statement and will …

πŸ“… Published: June 3, 2025, 8:31 p.m. πŸ”„ Last Modified: June 5, 2025, 2:07 p.m.

8.7

CVSS4.0

CVE-2025-5527 - Tenda RX3 SetStaticRouteCfg save_staticroute_data stack-based overflow

A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the function save_staticroute_data of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotel…

πŸ“… Published: June 3, 2025, 8:31 p.m. πŸ”„ Last Modified: June 9, 2025, 3:11 p.m.

6.3

CVSS4.0

CVE-2025-5525 - Jrohy trojan linux.go LogChan os command injection

A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/util/linux.go. The manipulation of the argument c leads to os command injection. The attack can be initiated remotely. The complexity of an at…

πŸ“… Published: June 3, 2025, 8 p.m. πŸ”„ Last Modified: June 6, 2025, 5:27 p.m.

5.1

CVSS4.0

CVE-2025-5523 - enilu web-flash File Upload upload fileService.upload cross site scripting

A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripti…

πŸ“… Published: June 3, 2025, 7:31 p.m. πŸ”„ Last Modified: June 9, 2025, 3:12 p.m.
Total resulsts: 346616
Page 4928 of 34,662
Β« previous page Β» next page
Filters