5.1

CVSS4.0

CVE-2025-3999 - Seeyon Zhiyuan OA Web Application System URL Parameter date.jsp cross site scripting

A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unknown processing of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\common\js\addDate\date.jsp of the component URL Parameter Handler. The …

πŸ“… Published: April 28, 2025, 3:31 a.m. πŸ”„ Last Modified: Jan. 15, 2026, 4:24 p.m.

6.9

CVSS4.0

CVE-2025-3998 - CodeAstro Membership Management System renew.php sql injection

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…

πŸ“… Published: April 28, 2025, 3 a.m. πŸ”„ Last Modified: May 14, 2025, 7:49 p.m.

6.1

CVSS3.1

CVE-2025-3706 - 104 Corporation eHRMS - Reflected Cross-Site Scripting

The eHRMS from 104 Corporation has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

πŸ“… Published: April 28, 2025, 2:39 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-3997 - dazhouda lecms Personal Information Page index.php cross-site request forgery

A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-profile-ajax-1 of the component Personal Information Page. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. T…

πŸ“… Published: April 28, 2025, 2:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-3996 - TOTOLINK N150RT MAC Filtering Page home.htm cross site scripting

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /home.htm of the component MAC Filtering Page. The manipulation of the argument Comment leads to cross site scripting. The attack may be l…

πŸ“… Published: April 28, 2025, 2 a.m. πŸ”„ Last Modified: May 28, 2025, 3:16 p.m.

4.8

CVSS4.0

CVE-2025-3995 - TOTOLINK N150RT LAN Settings Page fromStaticDHCP cross site scripting

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /boafrm/fromStaticDHCP of the component LAN Settings Page. The manipulation of the argument Hostname leads to cross site scriptin…

πŸ“… Published: April 28, 2025, 1:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:30 p.m.

4.8

CVSS4.0

CVE-2025-3994 - TOTOLINK N150RT IP Port Filtering home.htm cross site scripting

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unknown function of the file /home.htm of the component IP Port Filtering. The manipulation of the argument Comment leads to cross site scripting. It is possible to launch the attack …

πŸ“… Published: April 28, 2025, 1 a.m. πŸ”„ Last Modified: May 12, 2025, 7:30 p.m.

8.7

CVSS4.0

CVE-2025-3993 - TOTOLINK N150RT formWsc buffer overflow

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This issue affects some unknown processing of the file /boafrm/formWsc. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed…

πŸ“… Published: April 28, 2025, 12:31 a.m. πŸ”„ Last Modified: May 12, 2025, 7:31 p.m.

8.7

CVSS4.0

CVE-2025-3992 - TOTOLINK N150RT formWlwds buffer overflow

A vulnerability has been found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWlwds. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been discl…

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: May 12, 2025, 7:31 p.m.

3.5

CVSS3.1

CVE-2023-35815 -

DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

πŸ“… Published: April 28, 2025, midnight πŸ”„ Last Modified: June 5, 2025, 2:29 p.m.
Total resulsts: 349182
Page 5649 of 34,919
Β« previous page Β» next page
Filters