NA - CVE-2025-43484 - A potential reflected cross-site scripting...
A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input...
NA - CVE-2025-43485 - A potential security
vulnerability has been...
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials...
NA - CVE-2025-43486 - A potential stored cross-site scripting...
A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without...
NA - CVE-2025-43487 - A potential privilege escalation through Sudo...
A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The firmware flaw does not properly implement access...
NA - CVE-2025-43488 - A potential security vulnerability has been...
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a bypass of the application's XSS filter by...
NA - CVE-2025-43489 - A potential security vulnerability has been...
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize untrusted data without validation. HP has...
NA - CVE-2025-54139 - HAX CMS allows users to manage their microsite...
HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 and below and in haxcms-php versions 11.0.7 and below, all pages within the...
NA - CVE-2025-54120 - PCL (Plain Craft Launcher) Community Edition is...
PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are...
High - CVE-2025-8060 - A vulnerability has been found in Tenda AC23...
A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /goform/setMacFilterCfg of the component...
Medium - CVE-2025-5753 - The Valuation Calculator plugin for WordPress...
The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in all versions up to, and including, 1.3.2 due to insufficient input...