4.8

CVSS4.0

CVE-2025-5516 - TOTOLINK X2000R URL Filtering Page formFilter cross site scripting

A vulnerability, which was classified as problematic, was found in TOTOLINK X2000R 1.0.0-B20230726.1108. This affects an unknown part of the file /boafrm/formFilter of the component URL Filtering Page. The manipulation of the argument URL Address leads to cross site scripting. It is possible to ini…

📅 Published: June 3, 2025, 6 p.m. 🔄 Last Modified: June 6, 2025, 5:42 p.m.

6.5

CVSS3.1

CVE-2025-30360 - webpack-dev-server users' source code may be stolen when they access a malicious web site with non-…

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when you access a malicious web site with non-Chromium based browser. The `Origin` header is checked to prevent Cross-si…

📅 Published: June 3, 2025, 5:41 p.m. 🔄 Last Modified: Nov. 21, 2025, 6:26 p.m.

5.3

CVSS3.1

CVE-2025-30359 - webpack-dev-server users' source code may be stolen when they access a malicious web site

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when they access a malicious web site. Because the request for classic script by a script tag is not subject to same ori…

📅 Published: June 3, 2025, 5:39 p.m. 🔄 Last Modified: Oct. 3, 2025, 1:12 a.m.

5.3

CVSS4.0

CVE-2025-5515 - TOTOLINK X2000R formMapDel command injection

A vulnerability, which was classified as critical, has been found in TOTOLINK X2000R 1.0.0-B20230726.1108. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel. The manipulation of the argument devicemac1 leads to command injection. The attack may be launched remotely…

📅 Published: June 3, 2025, 5:31 p.m. 🔄 Last Modified: June 17, 2025, 8:40 p.m.

5.1

CVSS4.0

CVE-2025-5513 - quequnlong shiyi-blog add cross site scripting

A vulnerability has been found in quequnlong shiyi-blog up to 1.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/api/comment/add. The manipulation of the argument content leads to cross site scripting. The attack can be launched remo…

📅 Published: June 3, 2025, 5:31 p.m. 🔄 Last Modified: Oct. 3, 2025, 1:07 a.m.

6.9

CVSS4.0

CVE-2025-5512 - quequnlong shiyi-blog Administrator Backend verifyPassword improper authentication

A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file /api/sys/user/verifyPassword/ of the component Administrator Backend. The manipulation leads to improper authentication. It is possible to launch the attack…

📅 Published: June 3, 2025, 5 p.m. 🔄 Last Modified: Oct. 3, 2025, 1:14 a.m.

6.9

CVSS4.0

CVE-2025-5511 - quequnlong shiyi-blog photos improper authorization

A vulnerability, which was classified as critical, has been found in quequnlong shiyi-blog up to 1.2.1. This issue affects some unknown processing of the file /dev api/app/album/photos/. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been dis…

📅 Published: June 3, 2025, 5 p.m. 🔄 Last Modified: Oct. 3, 2025, 1:15 a.m.

7.3

CVSS3.1

CVE-2025-30167 - Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerabili…

Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create conf…

📅 Published: June 3, 2025, 4:42 p.m. 🔄 Last Modified: Jan. 23, 2026, 5:16 p.m.

5.3

CVSS4.0

CVE-2025-5510 - quequnlong shiyi-blog optimize server-side request forgery

A vulnerability classified as critical was found in quequnlong shiyi-blog up to 1.2.1. This vulnerability affects unknown code of the file /app/sys/article/optimize. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit has been…

📅 Published: June 3, 2025, 4:31 p.m. 🔄 Last Modified: June 9, 2025, 3:13 p.m.

5.3

CVSS4.0

CVE-2025-5509 - quequnlong shiyi-blog upload path traversal

A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload. The manipulation of the argument file/source leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed…

📅 Published: June 3, 2025, 4 p.m. 🔄 Last Modified: June 9, 2025, 3:14 p.m.
Total resulsts: 346618
Page 4930 of 34,662
« previous page » next page
Filters