NA - CVE-2024-56192 - In wl_notify_gscan_event of wl_cfgscan.c, there...
In wl_notify_gscan_event of wl_cfgscan.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution...
NA - CVE-2025-0660 - Concrete CMS versions 9.0.0 through 9.3.9 are...
Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality lacks input sanitization, allowing a rogue admin to inject XSS payloads as...
NA - CVE-2025-1920 - Type Confusion in V8 in Google Chrome prior to...
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
NA - CVE-2025-2135 - Type Confusion in V8 in Google Chrome prior to...
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
NA - CVE-2025-2136 - Use after free in Inspector in Google Chrome...
Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
NA - CVE-2025-2137 - Out of bounds read in V8 in Google Chrome prior...
Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
NA - CVE-2025-25907 - tianti v2.3 was discovered to contain a...
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or...
NA - CVE-2025-25908 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the coverImageURL parameter at...
NA - CVE-2025-27910 - tianti v2.3 was discovered to contain a...
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a crafted...
NA - CVE-2025-27610 - Rack provides an interface for developing web...
Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack::Static` can serve files under the specified `root:` even if `urls:` are...