6.4

CVSS3.1

CVE-2025-4775 - WordPress Infinite Scroll – Ajax Load More <= 7.4.0.1 - Authenticated(Contributor+) Stored Cross-Si…

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticate…

πŸ“… Published: June 17, 2025, 1:44 a.m. πŸ”„ Last Modified: April 21, 2026, 8:15 p.m.

7.2

CVSS3.1

CVE-2025-3774 - Wise Chat <= 3.3.4 - Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header

The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

πŸ“… Published: June 17, 2025, 1:44 a.m. πŸ”„ Last Modified: April 21, 2026, 8:15 p.m.

5.3

CVSS4.0

CVE-2025-6152 - Steel Browser files.routes.ts handleFileUpload path traversal

A vulnerability, which was classified as critical, was found in Steel Browser up to 0.1.3. This affects the function handleFileUpload of the file api/src/modules/files/files.routes.ts. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely.…

πŸ“… Published: June 17, 2025, 1:31 a.m. πŸ”„ Last Modified: July 2, 2025, 7:47 p.m.

8.2

CVSS4.0

CVE-2025-6151 - TP-Link TL-WR940N, TL-WR841N WanSlaacCfgRpm.htm buffer overflow

A vulnerability has been found in TP-Link TL-WR940N V4 and TL-WR841N V11. Affected by this issue is some unknown functionality of the file /userRpm/WanSlaacCfgRpm.htm, which may lead to buffer overflow. The attack may be launched remotely. This vulnerability only affects products that are no lon…

πŸ“… Published: June 17, 2025, 1 a.m. πŸ”„ Last Modified: July 15, 2025, 7:15 p.m.

5.3

CVSS4.0

CVE-2025-48993 - Group-Office vulnerable to reflected XSS via Look and Feel Formatting input

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the Look and Feel formatting fields. Any user can update their Look and Feel Formatting input fields, but the web application …

πŸ“… Published: June 17, 2025, 12:43 a.m. πŸ”„ Last Modified: Sept. 4, 2025, 3:57 p.m.

8.7

CVSS4.0

CVE-2025-6150 - TOTOLINK X15 HTTP POST Request formMultiAP buffer overflow

A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The att…

πŸ“… Published: June 17, 2025, 12:31 a.m. πŸ”„ Last Modified: June 23, 2025, 7:28 p.m.

8.7

CVSS4.0

CVE-2025-6149 - TOTOLINK A3002R HTTP POST Request formSysLog buffer overflow

A vulnerability classified as critical has been found in TOTOLINK A3002R 4.0.0-B20230531.1404. Affected is an unknown function of the file /boafrm/formSysLog of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch th…

πŸ“… Published: June 17, 2025, 12:31 a.m. πŸ”„ Last Modified: June 23, 2025, 7:28 p.m.

8.7

CVSS4.0

CVE-2025-6148 - TOTOLINK A3002RU HTTP POST Request formSysLog buffer overflow

A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formSysLog of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack m…

πŸ“… Published: June 17, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:28 p.m.

8.7

CVSS4.0

CVE-2025-6147 - TOTOLINK A702R HTTP POST Request formSysLog buffer overflow

A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formSysLog of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can…

πŸ“… Published: June 17, 2025, midnight πŸ”„ Last Modified: June 23, 2025, 7:29 p.m.

7.3

CVSS3.1

CVE-2025-49179 - Xorg-x11-server-xwayland: xorg-x11-server: tigervnc: integer overflow in x record extension

A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length checks.

πŸ“… Published: June 17, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5014 of 34,919
Β« previous page Β» next page
Filters