NA - CVE-2025-3464 - A race condition vulnerability exists in...
A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security...
NA - CVE-2025-40726 - Reflected Cross-Site Scripting (XSS)...
Reflected Cross-Site Scripting (XSS) vulnerability in /pages/search-results-page in Nosto, which allows remote attackers to execute arbitrary code via the q GET request parameter.
NA - CVE-2025-40727 - A Reflected Cross Site Scripting (XSS)...
A Reflected Cross Site Scripting (XSS) vulnerability was found in '/search' in Phoenix Site CMS from Phoenix, which allows remote attackers to execute arbitrary code via 's' GET...
NA - CVE-2025-40728 - SQL injection vulnerability in Customer Support...
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the...
NA - CVE-2025-40729 - Reflected Cross-Site Scripting (XSS) in...
Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter.
High - CVE-2025-6114 - A vulnerability has been found in D-Link...
A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is the function form_portforwarding of the file /goform/form_portforwarding. The...
High - CVE-2025-6115 - A vulnerability was found in D-Link DIR-619L...
A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function form_macfilter. The manipulation of the argument...
High - CVE-2025-25264 - An unauthenticated remote attacker can take...
An unauthenticated remote attacker can take advantage of the current overly permissive CORS policy to gain access and read the responses, potentially exposing sensitive data or enabling further...
High - CVE-2025-25265 - A web application for configuring the...
A web application for configuring the controller is accessible at a specific path. It contains an endpoint that allows an unauthenticated remote attacker to read files from the system’s file...