8.8
CVE-2025-49126 - Visionatrix Vulnerable to Reflected XSS Leading to Exfiltration of Secrets
Visionatrix is an AI Media processing tool using ComfyUI. In versions 1.5.0 to before 2.5.1, the /docs/flows endpoint is vulnerable to a Reflected XSS (Cross-Site Scripting) attack allowing full takeover of the application and exfiltration of secrets stored in the application. The implementation usβ¦
4.8
CVE-2025-6516 - HDF5 H5Fint.c H5F_addr_decode_len heap-based overflow
A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function H5F_addr_decode_len of the file /hdf5/src/H5Fint.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed toβ¦
8.7
CVE-2025-6511 - Netgear EX6150 sub_410090 stack-based overflow
A vulnerability classified as critical has been found in Netgear EX6150 1.0.0.46_1.0.76. This affects the function sub_410090. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
8.7
CVE-2025-6510 - Netgear EX6100 sub_415EF8 stack-based overflow
A vulnerability was found in Netgear EX6100 1.0.2.28_1.1.138. It has been rated as critical. Affected by this issue is the function sub_415EF8. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
5.1
CVE-2025-6509 - seaswalker spring-analysis SimpleController.java echo cross site scripting
A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been declared as problematic. Affected by this vulnerability is the function echo of the file /src/main/java/controller/SimpleController.java. The manipulation of the argument Name leads tβ¦
4.8
CVE-2025-52879 -
In JetBrains TeamCity before 2025.03.3 reflected XSS in the NPM Registry integration was possible
4.3
CVE-2025-52878 -
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
4.8
CVE-2025-52877 -
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
5.4
CVE-2025-52876 -
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
5.4
CVE-2025-52875 -
In JetBrains TeamCity before 2025.03.3 a DOM-based XSS at the Performance Monitor page was possible