Currently trending CVE - Hype Score: 9 - Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with ...
Currently trending CVE - Hype Score: 7 - Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Currently trending CVE - Hype Score: 15 - SSL Pinning Bypass in eWeLink Some hardware products allows local ATTACKER to Decrypt TLS communication and Extract secrets to clone the device via Flash the modified firmware
Currently trending CVE - Hype Score: 15 - When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.
The recent mass-theft of authentication tokens from Salesloft, whose AI chatbot is used by a broad swath of corporate America to convert customer interaction into Salesforce leads, has left many companies racing to invalidate the stolen credentials before hackers can exploit them. Now Google warns the breach goes far beyond access to Salesforce data, noting the hackers responsible also stole valid authentication tokens for hundreds of online services that customers can integrate with Salesloft, including Slack, Google Workspace, Amazon S3, Microsoft Azure, and OpenAI.
A vulnerability labeled as critical has been found in IBM Sterling Connect:Direct Web Services 6.1.0/6.2.0/6.3.0. This impacts an unknown function. Executing manipulation can lead to incorrect authorization.
The identification of this vulnerability is CVE-2024-49808. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability classified as problematic has been found in Khanakag-17 Library Management System up to 60ed174506094dcd166e34904a54288e5d10ff24. This affects an unknown function of the file /index.php. The manipulation of the argument msg leads to cross site scripting.
This vulnerability is referenced as CVE-2025-9755. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
A vulnerability classified as problematic was found in Synology RADIUS Server. This vulnerability affects unknown code. Executing manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2024-13987. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Sunnet eHRD CTMS. It has been classified as problematic. The affected element is an unknown function. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-9567. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in Sunnet eHRD CTMS. It has been declared as problematic. The impacted element is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-9568. The attack can be executed remotely. There is not any exploit available.
A vulnerability categorized as problematic has been discovered in Sunnet eHRD CTMS. This impacts an unknown function. Executing manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2025-9569. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as critical has been detected in libretro libretro-common. Affected by this vulnerability is the function cdfs_open_cue_track. This manipulation causes out-of-bounds write.
This vulnerability is registered as CVE-2025-9809. The attack needs to be launched locally. No exploit is available.
You should upgrade the affected component.
A vulnerability was found in Tenda AC20 16.03.08.05. It has been rated as critical. This vulnerability affects unknown code of the file /goform/fromAdvSetMacMtuWan. This manipulation of the argument wanMTU causes stack-based buffer overflow.
This vulnerability is registered as CVE-2025-9791. Remote exploitation of the attack is possible. Furthermore, an exploit is available.