Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-05-05 CVE-2025-4271 Improper Access Control vulnerability in Totolink A720R Firmware 4.1.5Cu.374
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374.
network
low complexity
totolink CWE-284
5.3
2025-05-05 CVE-2025-4268 Missing Authentication for Critical Function vulnerability in Totolink A720R Firmware 4.1.5Cu.374
A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical.
network
low complexity
totolink CWE-306
5.3
2025-05-05 CVE-2025-4269 Incorrect Privilege Assignment vulnerability in Totolink A720R Firmware 4.1.5Cu.374
A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical.
network
low complexity
totolink CWE-266
5.3
2025-05-05 CVE-2025-39363 Cross-site Scripting vulnerability in Alphaefficiencyteam Custom Login and Registration
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AlphaEfficiencyTeam Custom Login and Registration allows Stored XSS.This issue affects Custom Login and Registration: from n/a through 1.0.0.
network
low complexity
alphaefficiencyteam CWE-79
5.4
2025-05-05 CVE-2025-3583 Cross-site Scripting vulnerability in Thenewsletterplugin Newsletter
The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
thenewsletterplugin CWE-79
4.8
2025-05-05 CVE-2025-4266 Injection vulnerability in Anujk305 Notice Board System 1.0
A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0.
network
low complexity
anujk305 CWE-74
critical
9.8
2025-05-05 CVE-2025-4267 Injection vulnerability in Oretnom23 Stock Management System 1.0
A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0.
network
low complexity
oretnom23 CWE-74
7.2
2025-05-05 CVE-2025-4264 Injection vulnerability in PHPgurukul Emergency Ambulance Hiring Portal 1.0
A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0.
network
low complexity
phpgurukul CWE-74
critical
9.8
2025-05-05 CVE-2025-4265 Injection vulnerability in PHPgurukul Emergency Ambulance Hiring Portal 1.0
A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0.
network
low complexity
phpgurukul CWE-74
critical
9.8
2025-05-05 CVE-2025-4262 Injection vulnerability in PHPgurukul Online DJ Booking Management System 1.0
A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0.
network
low complexity
phpgurukul CWE-74
critical
9.8