9.3

CVSS4.0

CVE-2025-46274 - Planet Technology Network Products Use of Hard-coded Credentials

UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create entries in the managed database.

πŸ“… Published: April 24, 2025, 10:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-46273 - Planet Technology Network Products Use of Hard-coded Credentials

UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges to all UNI-NMS managed devices.

πŸ“… Published: April 24, 2025, 10:57 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-46272 - Planet Technology Network Products OS Command Injection

WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system.

πŸ“… Published: April 24, 2025, 10:56 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2025-46271 - Planet Technology Network Products OS Command Injection

UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.

πŸ“… Published: April 24, 2025, 10:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2025-1294 - eForm <= 4.18.0 - Unauthenticated Stored Cross-Site Scripting

The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.18.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…

πŸ“… Published: April 24, 2025, 10:22 p.m. πŸ”„ Last Modified: April 22, 2026, 1:45 a.m.

6.4

CVSS3.1

CVE-2025-3749 - Breeze Display <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via cal_size Par…

The Breeze Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜cal_size’ parameter in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…

πŸ“… Published: April 24, 2025, 10:22 p.m. πŸ”„ Last Modified: April 22, 2026, 1:45 a.m.

4.4

CVSS3.1

CVE-2025-43861 - ManageWiki Vulnerable to Self-XSS in review dialog via unsanitized field reflection

ManageWiki is a MediaWiki extension allowing users to manage wikis. Prior to commit 2f177dc, ManageWiki is vulnerable to reflected or stored XSS in the review dialog. A logged-in attacker must change a form field to include a malicious payload. If that same user then opens the "Review Changes" dial…

πŸ“… Published: April 24, 2025, 8:49 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 3:41 p.m.

4.6

CVSS3.1

CVE-2022-44759 - HCL Leap is affected by Cross-site scripting (XSS)

Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.

πŸ“… Published: April 24, 2025, 8:38 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

4.6

CVSS3.1

CVE-2022-44760 - HCL Leap is affected by an unrestricted upload of file with dangerous type vulnerability

Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.

πŸ“… Published: April 24, 2025, 8:37 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.

3.2

CVSS3.1

CVE-2023-37516 - HCL Leap is affected by missing "no cache" headers

Missing "no cache" headers in HCL Leap permits user directory information to be cached.

πŸ“… Published: April 24, 2025, 8:37 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 9:48 p.m.
Total resulsts: 349182
Page 5668 of 34,919
Β« previous page Β» next page
Filters