High - CVE-2025-6146 - A vulnerability was found in TOTOLINK X15...
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. This affects an unknown part of the file /boafrm/formSysLog of the component HTTP POST Request...
NA - CVE-2025-48993 - Group-Office is an enterprise customer...
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.123 and 25.0.27, a malicious JavaScript payload can be executed via the Look and Feel...
High - CVE-2025-6147 - A vulnerability was found in TOTOLINK A702R...
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formSysLog of the component HTTP POST...
High - CVE-2025-6148 - A vulnerability was found in TOTOLINK A3002RU...
A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formSysLog of the component HTTP...
High - CVE-2025-6149 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in TOTOLINK A3002R 4.0.0-B20230531.1404. Affected is an unknown function of the file /boafrm/formSysLog of the component HTTP POST Request...
High - CVE-2025-6150 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the component...
High - CVE-2025-6151 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in TP-Link TL-WR940N V4. Affected by this issue is some unknown functionality of the file /userRpm/WanSlaacCfgRpm.htm. The...
High - CVE-2025-3774 - The Wise Chat plugin for WordPress is...
The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all versions up to, and including, 3.3.4 due to insufficient input sanitization and...
Medium - CVE-2025-4775 - The WordPress Infinite Scroll – Ajax Load More...
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-button-label HTML attribute in all versions up to, and including,...