Medium - CVE-2025-4295 - Improper Validation of Certificate with Host...
Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting.This issue affects B2B: before 04.06.2025.
NA - CVE-2025-51867 - Insecure Direct Object Reference (IDOR)...
Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM using other users' credits via sensitive...
High - CVE-2025-8017 - A vulnerability was found in Tenda AC7...
A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg of the component httpd. The...
Low - CVE-2025-4878 - A vulnerability was found in libssh, where an...
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the...
NA - CVE-2025-51858 - Self Cross-Site Scripting (XSS) vulnerability...
Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent...
NA - CVE-2025-51859 - Stored Cross-Site Scripting (XSS) vulnerability...
Stored Cross-Site Scripting (XSS) vulnerability in Chaindesk thru 2025-05-26 in its agent chat component. An attacker can achieve arbitrary client-side script execution by crafting an AI agent...
NA - CVE-2025-51860 - Stored Cross-Site Scripting (XSS) in TelegAI...
Stored Cross-Site Scripting (XSS) in TelegAI (telegai.com) 2025-05-26 in its chat component and character container component. An attacker can achieve arbitrary client-side script execution by...
NA - CVE-2025-51862 - Insecure Direct Object Reference (IDOR)...
Insecure Direct Object Reference (IDOR) vulnerability in TelegAI (telegai.com) thru 2025-05-26 in its chat component. An attacker can exploit this IDOR to tamper other users' conversation....
NA - CVE-2025-51863 - Self Cross Site Scripting (XSS) vulnerability...
Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface.
NA - CVE-2025-51864 - A reflected cross-site scripting (XSS)...
A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, allowing attackers to hijack accounts through stolen JWT tokens.