6.1

CVSS3.1

CVE-2025-29573 -

Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 16, 2025, 8:19 p.m.

6.1

CVSS3.1

CVE-2025-27921 -

A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization o…

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 13, 2025, 6:40 p.m.

5.4

CVSS3.1

CVE-2025-45236 -

A stored cross-site scripting (XSS) vulnerability in the Edit Profile feature of DBSyncer v2.0.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Nickname parameter.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 7:54 p.m.

6.5

CVSS3.1

CVE-2024-57234 -

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:42 p.m.

6.5

CVSS3.1

CVE-2024-57230 -

NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:41 p.m.

9.8

CVSS3.1

CVE-2025-45042 -

Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:39 p.m.

7.5

CVSS3.1

CVE-2025-45617 -

Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensitive information via a crafted payload.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 3:03 p.m.

7.5

CVSS3.1

CVE-2025-45613 -

Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive information via a crafted payload.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: Oct. 14, 2025, 8:47 p.m.

8.8

CVSS3.1

CVE-2025-45322 -

kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: May 7, 2025, 4:40 p.m.

7.7

CVSS3.1

CVE-2025-45242 -

Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.

πŸ“… Published: May 5, 2025, midnight πŸ”„ Last Modified: June 17, 2025, 2:12 p.m.
Total resulsts: 346649
Page 5303 of 34,665
Β« previous page Β» next page
Filters