NA - CVE-2025-43924 - Cross Site Scripting vulnerability was...
Cross Site Scripting vulnerability was discovered in Unicom Focal Point 7.6.1. The val parameter in SettingController (for /fp/admin/settings/loginpage) and the rootserviceurl parameter in...
NA - CVE-2025-46548 - If you enable Basic Authentication in Pekko...
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management...
High - CVE-2025-5503 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the function formMapReboot of the file /boafrm/formMapReboot. The manipulation of the...
Medium - CVE-2025-5504 - A vulnerability has been found in TOTOLINK...
A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWsc. The manipulation of the...
Low - CVE-2025-5505 - A vulnerability was found in TOTOLINK A3002RU...
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual...
Low - CVE-2025-5506 - A vulnerability was found in TOTOLINK A3002RU...
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as problematic. Affected is an unknown function of the component NAT Mapping Page. The manipulation of the...
Medium - CVE-2025-1334 - IBM QRadar Suite Software 1.10.12.0 through...
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.
Medium - CVE-2025-25019 - IBM QRadar Suite Software 1.10.12.0 through...
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate...