7.5
CVE-2025-3511 - Denial of Service via Unsanitized Quantity in Mitsubishi CCβLink IE TSN Modules
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link IE TSN FPGA module, CC-Link IE TSN Remote Station Communicatiβ¦
6.4
CVE-2025-3752 - Able Player, accessible HTML5 media player <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Sitβ¦
The Able Player, accessible HTML5 media player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βpreloadβ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wiβ¦
6.5
CVE-2025-3775 - ShopLentor β WooCommerce Builder for Elementor & Gutenberg +20 Modules β All in One Solution (formeβ¦
The ShopLentor β WooCommerce Builder for Elementor & Gutenberg +20 Modules β All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This makes it possible for uβ¦
8.2
CVE-2025-43865 - React Router allows pre-render data spoofing on React-Router framework mode
React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ββof the data object passed to the HTML. This issue has been β¦
7.5
CVE-2025-43864 - React Router allows a DoS via cache poisoning by forcing SPA mode
React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the pagβ¦
9.9
CVE-2025-46616 -
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
7.5
CVE-2025-32982 -
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.
6.4
CVE-2025-46544 -
In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.
6.5
CVE-2025-32979 -
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.
2.4
CVE-2024-57375 -
Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to cause a denial of service (application crash) via certain deselect actions.