NA - CVE-2025-25767 - A vertical privilege escalation vulnerability...
A vertical privilege escalation vulnerability in the component /controller/UserController.java of MRCMS v3.1.2 allows attackers to arbitrarily delete users via a crafted request.
NA - CVE-2025-25768 - MRCMS v3.1.2 was discovered to contain a...
MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute...
NA - CVE-2025-25772 - A Cross-Site Request Forgery (CSRF) in the...
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
High - CVE-2025-1555 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to...
NA - CVE-2025-25282 - RAGFlow is an open-source RAG...
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR)...
NA - CVE-2019-8900 - A vulnerability in the SecureROM of some Apple...
A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows...