High - CVE-2025-6163 - A vulnerability was found in TOTOLINK A3002RU...
A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMultiAP of the component...
NA - CVE-2025-5209 - The Ivory Search WordPress plugin before...
The Ivory Search WordPress plugin before 5.5.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even...
High - CVE-2025-6164 - A vulnerability was found in TOTOLINK A3002R...
A vulnerability was found in TOTOLINK A3002R 4.0.0-B20230531.1404. It has been classified as critical. This affects an unknown part of the file /boafrm/formMultiAP of the component HTTP POST...
High - CVE-2025-6165 - A vulnerability was found in TOTOLINK X15...
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formTmultiAP of the component HTTP POST...
Low - CVE-2025-6166 - A vulnerability was found in frdel Agent-Zero...
A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the function image_get of the file /python/api/image_get.py. The manipulation of the...
Medium - CVE-2025-6167 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function create_workflow of the file python_a2a/agent_flow/server/api.py. The...
Medium - CVE-2025-6173 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of...
NA - CVE-2025-40674 - Reflected Cross-Site Scripting (XSS) in...
Reflected Cross-Site Scripting (XSS) in osCommerce v4. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the...
High - CVE-2025-3515 - The Drag and Drop Multiple File Upload for...
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including,...
NA - CVE-2025-6050 - Mezzanine CMS, in versions prior to 6.1.1,...
Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which...