9.3
CVE-2025-46274 - Planet Technology Network Products Use of Hard-coded Credentials
UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.
9.3
CVE-2025-46273 - Planet Technology Network Products Use of Hard-coded Credentials
UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.
9.3
CVE-2025-46272 - Planet Technology Network Products OS Command Injection
WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system.
9.3
CVE-2025-46271 - Planet Technology Network Products OS Command Injection
UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.
7.2
CVE-2025-1294 - eForm <= 4.18.0 - Unauthenticated Stored Cross-Site Scripting
The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pagesβ¦
6.4
CVE-2025-3749 - Breeze Display <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via cal_size Parβ¦
The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βcal_sizeβ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level accessβ¦
4.4
CVE-2025-43861 - ManageWiki Vulnerable to Self-XSS in review dialog via unsanitized field reflection
ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review dialog. A logged-in attacker must change a form field to include a malicious payload. If that same user then opens the "Review Changes" dialβ¦
4.6
CVE-2022-44759 - HCL Leap is affected by Cross-site scripting (XSS)
Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
4.6
CVE-2022-44760 - HCL Leap is affected by an unrestricted upload of file with dangerous type vulnerability
Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
3.2
CVE-2023-37516 - HCL Leap is affected by missing "no cache" headers
Missing "no cache" headers in HCL Leap permits user directory information to be cached.