Startseite > Computer & Technik > Internet > Marketing > scip AG [Security - Consulting - Information - Process] | RSS Verzeichnis

scip AG [Security - Consulting - Information - Process]


Anzeigen einer beliebigen Anzahl von Sicherheitsl?cken aus der scip AG Datenbank.

Betreiber-URL: https://www.scip.ch
RSS-Feed-URL: https://www.scip.ch/alertRSS.xml
Die neuesten Einträge aus dem RSS-Feed von scip AG [Security - Consulting - Information - Process]:
CVE-2025-43917 | Pritunl Client 1.2.2550.20 /Applications authorization
20.04.2025 00:26
A vulnerability has been found in Pritunl Client 1.2.2550.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /Applications. The manipulation leads to...
CVE-2023-26819 | cJSON 1.7.15 JSON Document expected behavior violation
20.04.2025 00:26
A vulnerability, which was classified as problematic, was found in cJSON 1.7.15. Affected is an unknown function of the component JSON Document Handler. The manipulation leads to expected behavior vio...
CVE-2023-30421 | mjson 1.2.7 mystrtod algorithmic complexity
20.04.2025 00:25
A vulnerability, which was classified as problematic, has been found in mjson 1.2.7. This issue affects some unknown processing of the component mystrtod. The manipulation leads to inefficient algorit...
CVE-2022-47112 | 7-Zip up to 24.09 xz File unusual condition
20.04.2025 00:25
A vulnerability classified as problematic was found in 7-Zip up to 24.09. This vulnerability affects unknown code of the component xz File Handler. The manipulation leads to improper check for unusual...
CVE-2022-47111 | 7-Zip up to 24.09 xz File unusual condition
20.04.2025 00:25
A vulnerability classified as problematic has been found in 7-Zip up to 24.09. This affects an unknown part of the component xz File Handler. The manipulation leads to improper check for unusual condi...
CVE-2025-43918 | SSL.com up to 2025-04-18 TLS Certificate less trusted source
20.04.2025 00:24
A vulnerability was found in SSL.com up to 2025-04-18. It has been rated as problematic. Affected by this issue is some unknown functionality of the component TLS Certificate Handler. The manipulation...
CVE-2025-3830 | kuangstudy KuangSimpleBBS 1.0 QuestionController.java fileUpload editormd-image-file unrestricted upload
19.04.2025 20:30
A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. It has been declared as critical. Affected by this vulnerability is the function fileUpload of the file src/main/java/com/kuang/controller/Q...
CVE-2025-3829 | PHPGurukul Men Salon Management System 1.0 sales-reports-detail.php fromdate/todate sql injection
19.04.2025 20:24
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/sales-reports-detail.php. The manipulati...
CVE-2025-3828 | PHPGurukul Men Salon Management System 1.0 view-appointment.php?viewid=11 remark sql injection
19.04.2025 20:24
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The ma...
CVE-2025-3827 | PHPGurukul Men Salon Management System 1.0 forgot-password.php email sql injection
19.04.2025 20:24
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/forgot-password.php. The manipulatio...
CVE-2025-3826 | SourceCodester Web-based Pharmacy Product Management System 1.0 add-supplier.php txtsupplier_name/txtaddress cross site scripting
19.04.2025 16:21
A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file add-supplier.php. The manip...
CVE-2025-3825 | SourceCodester Web-based Pharmacy Product Management System 1.0 add-category.php txtcategory_name cross site scripting
19.04.2025 16:21
A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown functionality of the fil...
CVE-2025-3824 | SourceCodester Web-based Pharmacy Product Management System 1.0 add-product.php txtprice/txtproduct_name cross site scripting
19.04.2025 16:21
A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file add-produ...
CVE-2025-3823 | SourceCodester Web-based Pharmacy Product Management System 1.0 add-stock.php txttotalcost/txtproductID/txtprice/txtexpirydate cross site scripting
19.04.2025 16:21
A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. The manipulation...
CVE-2025-3822 | SourceCodester Web-based Pharmacy Product Management System 1.0 changepassword.php cross site scripting
19.04.2025 16:21
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file changepassword.ph...
CVE-2025-3821 | SourceCodester Web-based Pharmacy Product Management System 1.0 add-admin.php txtpassword/txtfullname/txtemail cross site scripting
19.04.2025 16:21
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file add-admin.php. Th...
CVE-2024-13926 | WP-Syntax Plugin up to 1.2 on WordPress Regular Expression resource consumption
19.04.2025 14:12
A vulnerability was found in WP-Syntax Plugin up to 1.2 on WordPress. It has been classified as problematic. This affects an unknown part of the component Regular Expression Handler. The manipulation ...
CVE-2025-3820 | Tenda W12/i24 3.0.0.4(2887)/3.0.0.5(3644) /bin/httpd cgiSysUplinkCheckSet hostIp1/hostIp2 stack-based overflow
19.04.2025 02:00
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysUplinkCheckSet of the file /bin/httpd. The manipulat...
CVE-2025-3819 | PHPGurukul Men Salon Management System 1.0 search-appointment.php searchdata sql injection
19.04.2025 01:58
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointmen...
CVE-2025-3818 | webpy web.py 0.70 web/db.py PostgresDB._process_insert_query seqname sql injection
19.04.2025 01:55
A vulnerability, which was classified as critical, was found in webpy web.py 0.70. Affected is the function PostgresDB._process_insert_query of the file web/db.py. The manipulation of the argument seq...
CVE-2025-3817 | SourceCodester Online Eyewear Shop 1.0 Master.php?f=delete_stock ID sql injection
19.04.2025 01:53
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /oews/classes/Master.php?f=delete_st...
CVE-2025-3816 | westboy CicadasCMS 2.0 Scheduled Task /system/schedule/save os command injection
19.04.2025 01:51
A vulnerability classified as critical was found in westboy CicadasCMS 2.0. This vulnerability affects unknown code of the file /system/schedule/save of the component Scheduled Task Handler. The manip...
CVE-2025-3661 | SB Chart block Plugin up to 1.2.6 on WordPress className cross site scripting
18.04.2025 23:44
A vulnerability classified as problematic has been found in SB Chart block Plugin up to 1.2.6 on WordPress. This affects an unknown part. The manipulation of the argument className leads to cross site...
CVE-2021-4455 | Smart Product Review up to 1.0.4 on WordPress unrestricted upload
18.04.2025 23:44
A vulnerability was found in Smart Product Review up to 1.0.4 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted ...
CVE-2025-3404 | codename065 Download Manager Plugin up to 3.3.12 on WordPress wp-config.php savePackage denial of service
18.04.2025 23:44
A vulnerability was found in codename065 Download Manager Plugin up to 3.3.12 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function savePackage of the file ...
CVE-2025-43903 | Freedesktop Poppler up to 25.03.x adbe.pkcs7.sha1 Signature NSSCryptoSignBackend.cc signature verification
18.04.2025 23:43
A vulnerability was found in Freedesktop Poppler up to 25.03.x. It has been classified as problematic. Affected is an unknown function of the file NSSCryptoSignBackend.cc of the component adbe.pkcs7.s...
CVE-2025-32953 | udo-munk z80pack up to 1.38 upload-artifact information disclosure (bd95916)
18.04.2025 23:10
A vulnerability was found in udo-munk z80pack up to 1.38 and classified as problematic. This issue affects some unknown processing of the component upload-artifact. The manipulation leads to informati...
CVE-2025-25984 | Macro-video V380E6_C1 IP Camera 1020302 UART Component hard-coded password
18.04.2025 23:09
A vulnerability has been found in Macro-video V380E6_C1 IP Camera 1020302 and classified as problematic. This vulnerability affects unknown code of the component UART Component. The manipulation leads...
CVE-2024-57493 | redoxOS relibc setsockopt denial of service (Issue 201)
18.04.2025 23:09
A vulnerability, which was classified as problematic, was found in redoxOS relibc. This affects the function setsockopt. The manipulation leads to denial of service. This vulnerability is uniquely id...
CVE-2025-28197 | Crawl4AI up to 0.4.247 async_dispatcher.py server-side request forgery
18.04.2025 23:08
A vulnerability, which was classified as critical, has been found in Crawl4AI up to 0.4.247. Affected by this issue is some unknown functionality of the file /crawl4ai/async_dispatcher.py. The manipul...
CVE-2025-36625 | Tenable Nessus up to 10.8.3 HTTP Request neutralization for logs
18.04.2025 23:08
A vulnerability classified as problematic was found in Tenable Nessus up to 10.8.3. Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler. The manipulation l...
CVE-2024-53591 | Seclore 3.27.5.0 Login Page excessive authentication
18.04.2025 23:08
A vulnerability classified as problematic has been found in Seclore 3.27.5.0. Affected is an unknown function of the component Login Page. The manipulation leads to improper restriction of excessive a...
CVE-2025-25985 | Macro-video V380E6_C1 IP Camera 1020302 /mnt/mtd/mvconf/wifi.ini credentials storage
18.04.2025 23:08
A vulnerability was found in Macro-video V380E6_C1 IP Camera 1020302. It has been rated as problematic. This issue affects some unknown processing of the file /mnt/mtd/mvconf/wifi.ini. The manipulatio...
CVE-2025-25983 | Macro-video V380 Pro 2.1.44/2.1.64 on Android QE Code information disclosure
18.04.2025 23:08
A vulnerability was found in Macro-video V380 Pro 2.1.44/2.1.64 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component QE Code Handler. The manipulat...
CVE-2025-32377 | RasaHQ Rosa Pro up to 3.9.19/3.10.18/3.11.6/3.12.5 audiocodes_stream missing authentication (GHSA-7xq5-54jp-2mfg)
18.04.2025 23:07
A vulnerability was found in RasaHQ Rosa Pro up to 3.9.19/3.10.18/3.11.6/3.12.5. It has been classified as critical. This affects the function audiocodes_stream. The manipulation leads to missing auth...
CVE-2025-29058 | Qimou CMS 3.34.0 upgrade.php privilege escalation
18.04.2025 23:07
A vulnerability was found in Qimou CMS 3.34.0 and classified as critical. Affected by this issue is some unknown functionality of the file upgrade.php. The manipulation leads to privilege escalation. ...
CVE-2025-29513 | NodeBB up to 4.0.4 Admin API Access Token cross site scripting
18.04.2025 21:09
A vulnerability has been found in NodeBB up to 4.0.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Admin API Access Token Handler. The mani...
CVE-2025-28355 | Volmarg Personal Management System 1.4.65 cross-site request forgery
18.04.2025 21:09
A vulnerability, which was classified as problematic, was found in Volmarg Personal Management System 1.4.65. Affected is an unknown function. The manipulation leads to cross-site request forgery. Th...
CVE-2025-24914 | Tenable Nessus up to 10.8.3 default permission
18.04.2025 21:08
A vulnerability, which was classified as critical, has been found in Tenable Nessus up to 10.8.3. This issue affects some unknown processing. The manipulation leads to incorrect default permissions. ...
CVE-2025-28242 | DAEnetIP4 METO 1.25 /login_ok.htm user session
18.04.2025 20:44
A vulnerability classified as problematic was found in DAEnetIP4 METO 1.25. This vulnerability affects unknown code of the file /login_ok.htm. The manipulation leads to manage user sessions. This vul...
CVE-2025-28238 | Elber REBLE310 5.5.1.R user session
18.04.2025 20:44
A vulnerability classified as problematic has been found in Elber REBLE310 5.5.1.R. This affects an unknown part. The manipulation leads to manage user sessions. This vulnerability is uniquely identi...
CVE-2025-28231 | Itel IP Stream 1.7.0.6 access control
18.04.2025 20:44
A vulnerability was found in Itel IP Stream 1.7.0.6. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls. This vuln...
CVE-2025-28237 | WorldCast Systems ECRESO FM DAB TV Transmitter 1.10.1 JSON privilege escalation
18.04.2025 20:43
A vulnerability was found in WorldCast Systems ECRESO FM DAB TV Transmitter 1.10.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component JSON H...
CVE-2025-29512 | NodeBB up to 4.0.4 Blacklist IP cross site scripting
18.04.2025 20:43
A vulnerability was found in NodeBB up to 4.0.4. It has been classified as problematic. Affected is an unknown function of the component Blacklist IP Handler. The manipulation leads to cross site scri...
CVE-2025-28233 | BW Broadcast TX50 1.7 access control
18.04.2025 20:43
A vulnerability was found in BW Broadcast TX600 14980, TX300 32990 31448, TX150, TX1000, TX30 and TX50 1.7 and classified as critical. This issue affects some unknown processing. The manipulation lead...
CVE-2025-1697 | HP Touchpoint Analytics Service prior 4.2.2439 link following
18.04.2025 20:42
A vulnerability has been found in HP Touchpoint Analytics Service and classified as critical. This vulnerability affects unknown code. The manipulation leads to link following. This vulnerability was...
CVE-2025-28235 | Soundcraft Ui12/Ui16 1.0.5x/1.0.7x /socket.io/1/websocket/ information disclosure
18.04.2025 20:41
A vulnerability, which was classified as problematic, was found in Soundcraft Ui12 and Ui16 1.0.5x/1.0.7x. This affects an unknown part of the file /socket.io/1/websocket/. The manipulation leads to i...
CVE-2025-28236 | Nautel VX up to 6.4.0 Update /#/software/upgrades privilege escalation
18.04.2025 20:41
A vulnerability, which was classified as very critical, has been found in Nautel VX up to 6.4.0. Affected by this issue is some unknown functionality of the file /#/software/upgrades of the component ...
CVE-2025-3809 | Debug Log Manager Plugin up to 2.3.4 on WordPress cross site scripting
18.04.2025 19:40
A vulnerability classified as problematic was found in Debug Log Manager Plugin up to 2.3.4 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross si...
CVE-2025-2111 | Insert Headers and Footers Plugin up to 3.1.1 on WordPress custom_plugin_set_option cross-site request forgery
18.04.2025 19:40
A vulnerability classified as problematic has been found in Insert Headers and Footers Plugin up to 3.1.1 on WordPress. Affected is the function custom_plugin_set_option. The manipulation leads to cro...
CVE-2025-3275 | Themesflat Addons for Elementor Plugin up to 2.2.5 on WordPress cross site scripting
18.04.2025 19:40
A vulnerability was found in Themesflat Addons for Elementor Plugin up to 2.2.5 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cr...
CVE-2025-1457 | Element Pack Addons for Elementor Plugin up to 5.10.28 on WordPress cross site scripting
18.04.2025 19:39
A vulnerability was found in Element Pack Addons for Elementor Plugin up to 5.10.28 on WordPress. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads t...
CVE-2025-3284 | User Registration & Membership Plugin up to 5.1.3 on WordPress user_registration_pro_delete_account cross-site request forgery
18.04.2025 19:39
A vulnerability was found in User Registration & Membership Plugin up to 5.1.3 on WordPress. It has been classified as problematic. This affects the function user_registration_pro_delete_account. The ...
CVE-2025-3278 | UrbanGo Membership Plugin up to 1.0.4 on WordPress user_register_role privileges management
18.04.2025 19:39
A vulnerability was found in UrbanGo Membership Plugin up to 1.0.4 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation of the argument user_...
CVE-2025-2010 | JobWP Plugin up to 2.3.9 on WordPress jobwp_upload_resume sql injection
18.04.2025 19:39
A vulnerability has been found in JobWP Plugin up to 2.3.9 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument jobwp_u...
CVE-2025-3103 | Clever Plugin up to 2.4 on WordPress history.php path traversal
18.04.2025 19:39
A vulnerability, which was classified as critical, was found in Clever Plugin up to 2.4 on WordPress. Affected is an unknown function of the file history.php. The manipulation leads to path traversal....
CVE-2025-1093 | AIHub Theme up to 1.3.7 on WordPress generate_image unrestricted upload
18.04.2025 19:38
A vulnerability, which was classified as critical, has been found in AIHub Theme up to 1.3.7 on WordPress. This issue affects the function generate_image. The manipulation leads to unrestricted upload...
CVE-2024-41447 | Alkacon OpenCMS 17.0 Article Author cross site scripting (Exploit 52209 / EDB-52209)
18.04.2025 19:37
A vulnerability classified as problematic was found in Alkacon OpenCMS 17.0. This vulnerability affects unknown code of the component Article Handler. The manipulation of the argument Author leads to ...
CVE-2025-28230 | JMBroadcast JMB0150 1.0 access control
18.04.2025 19:37
A vulnerability classified as problematic has been found in JMBroadcast JMB0150 1.0. This affects an unknown part. The manipulation leads to improper access controls. This vulnerability is uniquely i...
CVE-2025-28229 | Orban OPTIMOD 5950 1.0.0.2/2.2.15 access control
18.04.2025 19:36
A vulnerability was found in Orban OPTIMOD 5950 1.0.0.2/2.2.15. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to improper access controls....
CVE-2025-29209 | TOTOLINK X18 9.1.0cu.2024 cstecgi .cgi sub_41105C enable improper authorization
18.04.2025 19:36
A vulnerability was found in TOTOLINK X18 9.1.0cu.2024. It has been declared as critical. Affected by this vulnerability is the function sub_41105C of the file cstecgi .cgi. The manipulation of the ar...
CVE-2024-29643 | croogo 3.0.2 Header feed.rss Host injection
18.04.2025 19:35
A vulnerability was found in croogo 3.0.2. It has been classified as critical. Affected is an unknown function of the file feed.rss of the component Header Handler. The manipulation of the argument Ho...
CVE-2025-27599 | element-hq element-x-android up to 25.04.1 Hyperlink improper export of android application components (GHSA-m5px-pwq3-4p5m)
18.04.2025 19:35
A vulnerability was found in element-hq element-x-android up to 25.04.1 and classified as critical. This issue affects some unknown processing of the component Hyperlink Handler. The manipulation lead...
CVE-2025-32795 | langgenius dify up to 0.6.11 Role-Based Access Control access control (GHSA-gg5w-m2vw-vmmj)
18.04.2025 19:35
A vulnerability has been found in langgenius dify up to 0.6.11 and classified as critical. This vulnerability affects unknown code of the component Role-Based Access Control. The manipulation leads to...
CVE-2025-32796 | langgenius dify up to 0.6.11 Role-Based Access Control access control (GHSA-hqcx-598m-pjq4)
18.04.2025 19:34
A vulnerability, which was classified as critical, was found in langgenius dify up to 0.6.11. This affects an unknown part of the component Role-Based Access Control. The manipulation leads to imprope...
CVE-2025-30357 | NamelessMC Nameless up to 2.1.x name resolution (GHSA-22mc-7c9m-gv8h)
18.04.2025 19:34
A vulnerability, which was classified as problematic, has been found in NamelessMC Nameless up to 2.1.x. Affected by this issue is some unknown functionality. The manipulation leads to incorrectly-res...
CVE-2025-30158 | NamelessMC Nameless up to 2.1.x resource consumption (GHSA-2prx-rgr7-hq5f)
18.04.2025 19:34
A vulnerability classified as problematic was found in NamelessMC Nameless up to 2.1.x. Affected by this vulnerability is an unknown functionality. The manipulation leads to resource consumption. Thi...
CVE-2025-31120 | NamelessMC Nameless up to 2.1.x cookie validation (GHSA-8jv7-77jw-h646)
18.04.2025 19:34
A vulnerability classified as problematic has been found in NamelessMC Nameless up to 2.1.x. Affected is an unknown function. The manipulation leads to cookies without validation. This vulnerability ...
CVE-2025-32792 | endojs endo up to 1.11.x Compartment API exposure of sensitive system information to an unauthorized control sphere (GHSA-h9w6-f932-gq62)
18.04.2025 19:33
A vulnerability was found in endojs endo up to 1.11.x. It has been rated as problematic. This issue affects some unknown processing of the component Compartment API. The manipulation leads to exposure...
CVE-2025-32442 | Fastify up to 5.3.0 on Node.js improper validation of specified type of input (GHSA-mg2h-6x62-wpwc)
18.04.2025 19:32
A vulnerability was found in Fastify up to 5.3.0 on Node.js. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to improper validation of specified ty...
CVE-2025-29625 | Astrolog 7.70 Environment Variable FileOpen buffer overflow (Issue 25)
18.04.2025 19:32
A vulnerability was found in Astrolog 7.70. It has been classified as critical. This affects the function FileOpen of the component Environment Variable Handler. The manipulation leads to buffer overf...
CVE-2025-28059 | Nagios Network Analyzer 2024R1.0.3 session expiration
18.04.2025 19:31
A vulnerability was found in Nagios Network Analyzer 2024R1.0.3 and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to session expiration. This vu...
CVE-2025-29784 | NamelessMC Nameless up to 2.1.x GET Request length parameter (GHSA-4hrq-rf96-c2jm)
18.04.2025 19:31
A vulnerability has been found in NamelessMC Nameless up to 2.1.x and classified as problematic. Affected by this vulnerability is an unknown functionality of the component GET Request Handler. The ma...
CVE-2025-28228 | Electrolink DAB Transmitter Web missing encryption
18.04.2025 19:30
A vulnerability, which was classified as problematic, was found in Electrolink DAB Transmitter Web. Affected is an unknown function. The manipulation leads to missing encryption of sensitive data. Th...
CVE-2025-28232 | JMBroadcast JMB0150 1.0 Admin Panel HOME.php access control
18.04.2025 19:30
A vulnerability, which was classified as critical, has been found in JMBroadcast JMB0150 1.0. This issue affects some unknown processing of the file HOME.php of the component Admin Panel. The manipula...
CVE-2025-29953 | Apache ActiveMQ NMS OpenWire Client up to 2.1.0 deserialization
18.04.2025 19:30
A vulnerability classified as problematic was found in Apache ActiveMQ NMS OpenWire Client up to 2.1.0. This vulnerability affects unknown code. The manipulation leads to deserialization. This vulner...
CVE-2025-2950 | IBM i 7.3/7.4/7.5/7.6 domain/IP address http headers for scripting syntax
18.04.2025 19:29
A vulnerability classified as critical has been found in IBM i 7.3/7.4/7.5/7.6. This affects an unknown part. The manipulation of the argument domain/IP address leads to improper neutralization of htt...
CVE-2025-32434 | PyTorch up to 2.5.x deserialization (GHSA-53q9-r3pm-6pq6)
18.04.2025 19:29
A vulnerability was found in PyTorch up to 2.5.x. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to deserialization. This vulnerability is...
CVE-2025-32389 | NamelessMC Nameless up to 2.1.3 GET Parameter param sql injection (GHSA-5984-mhcp-cq2x)
18.04.2025 19:28
A vulnerability was found in NamelessMC Nameless up to 2.1.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component GET Parameter Handler. The m...
CVE-2025-37838 | Linux Kernel up to 4.19.309 HSI ssi_protocol_probe use after free
18.04.2025 19:28
A vulnerability was found in Linux Kernel. It has been classified as critical. Affected is the function ssi_protocol_probe of the component HSI. The manipulation leads to use after free. This vulnera...
CVE-2025-31118 | NamelessMC Nameless up to 2.1.x Forum Quick Reply view_topic.php resource consumption (GHSA-jhvp-mwj4-922m)
18.04.2025 19:28
A vulnerability was found in NamelessMC Nameless up to 2.1.x and classified as problematic. This issue affects some unknown processing of the file view_topic.php of the component Forum Quick Reply. Th...
CVE-2025-3808 | zhenfeng13 My-BBS 1.0 cross-site request forgery
18.04.2025 16:35
A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. This vulnerabilit...
CVE-2025-3807 | zhenfeng13 My-BBS 1.0 Endpoint UploadController.java upload unrestricted upload
18.04.2025 16:35
A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/UploadController.java of ...
CVE-2025-3806 | dazhouda lecms up to 3.0.3 Edit Profile /admin cross site scripting
18.04.2025 16:32
A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3. Affected by this issue is some unknown functionality of the file /admin of the component Edit Profil...
CVE-2025-3805 | sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec Jinja2 Template check_id.py ID injection (Issue 86)
18.04.2025 16:29
A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. Affected by this vulnerability is an unknown functionality of the file chec...
CVE-2025-3804 | thautwarm vscode-diana 0.0.1 Jinja2 Template Gen.py injection
18.04.2025 16:26
A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation lea...
CVE-2025-3803 | Tenda W12/i24 3.0.0.4(2887)/3.0.0.5(3644) /bin/httpd cgiSysScheduleRebootSet rebootDate stack-based overflow
18.04.2025 16:24
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysScheduleRebootSet of the file /bin/httpd. The manipulat...
CVE-2025-3802 | Tenda W12/i24 3.0.0.4(2887)/3.0.0.5(3644) /bin/httpd cgiPingSet pingIP stack-based overflow
18.04.2025 16:24
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function cgiPingSet of the file /bin/httpd. The manipulatio...
CVE-2025-3801 | songquanpeng one-api up to 0.6.10 System Setting Homepage Content cross site scripting
18.04.2025 16:21
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the arg...
CVE-2025-40364 | Linux Kernel up to 6.1.128/6.6.77 io_uring io_req_prep_async buffer overflow
18.04.2025 16:18
A vulnerability was found in Linux Kernel up to 6.1.128/6.6.77 and classified as critical. Affected by this issue is the function io_req_prep_async of the component io_uring. The manipulation leads to...
CVE-2025-3800 | WCMS 11 AnonymousController.php mobile_phone sql injection
18.04.2025 16:18
A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown functionality of the file app/controllers/AnonymousController.php. The manipulation o...
CVE-2025-3799 | WCMS 11 AnonymousController.php email/username sql injection
18.04.2025 16:18
A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app/controllers/AnonymousController.php. The manipulation of the argument email/use...
CVE-2025-3798 | WCMS 11 Advertisement Image AdvadminController.php sub unrestricted upload
18.04.2025 16:18
A vulnerability, which was classified as critical, has been found in WCMS 11. This issue affects the function sub of the file app/admin/AdvadminController.php of the component Advertisement Image Hand...
CVE-2025-3797 | SeaCMS up to 13.3 admin_topic.php?action=delall e_id sql injection
18.04.2025 16:10
A vulnerability classified as critical was found in SeaCMS up to 13.3. This vulnerability affects unknown code of the file /admin_topic.php?action=delall. The manipulation of the argument e_id leads t...
CVE-2025-3796 | PHPGurukul Men Salon Management System 1.0 /admin/contact-us.php pagetitle/pagedes/email/mobnumber/timing sql injection
18.04.2025 16:08
A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us.php. The manipulation of the argument pa...
CVE-2025-3795 | DaiCuo 1.3.13 SEO Optimization Settings Section cross site scripting
18.04.2025 16:05
A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO Optimization Settings Section. The manipulation ...
CVE-2024-46089 | 74CMS up to 3.33 Background Interface apiadmin privilege escalation
18.04.2025 15:20
A vulnerability was found in 74CMS up to 3.33. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Background Interface apiadmin. The manip...
CVE-2025-32790 | langgenius dify up to 0.6.12 /export access control
18.04.2025 14:46
A vulnerability was found in langgenius dify up to 0.6.12. It has been classified as critical. Affected is an unknown function of the file /export. The manipulation leads to improper access controls. ...
CVE-2024-49808 | IBM Sterling Connect:Direct Web Services 6.1.0/6.2.0/6.3.0 authorization
18.04.2025 14:45
A vulnerability was found in IBM Sterling Connect:Direct Web Services 6.1.0/6.2.0/6.3.0 and classified as critical. This issue affects some unknown processing. The manipulation leads to incorrect auth...
CVE-2024-45651 | IBM Sterling Connect:Direct Web Services 6.1.0/6.2.0/6.3.0 session expiration
18.04.2025 14:45
A vulnerability has been found in IBM Sterling Connect:Direct Web Services 6.1.0/6.2.0/6.3.0 and classified as critical. This vulnerability affects unknown code. The manipulation leads to session expi...
RSS Feed eintragen

Machen Sie Ihren RSS-Feed bekannt und erhöhen Sie die Sichtbarkeit Ihrer Website!

RSS-Feed eintragen
RSS-Reader
RSS-Reader finden Sie unter unsere Übersicht: RSS-Reader
Die neuesten Feeds
Die Top-Feeds
meist gelesenen Feeds