NA - CVE-2024-56882 - Sage DPW before 2024_12_000 is vulnerable to...
Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role privileges can permanently store JavaScript code in the Kurstitel and Kurzinfo...
NA - CVE-2024-56883 - Sage DPW before 2024_12_001 is vulnerable to...
Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee...
NA - CVE-2025-25300 - smartbanner.js is a customizable smart app...
smartbanner.js is a customizable smart app banner for iOS and Android. Prior to version 1.14.1, clicking on smartbanner `View` link and navigating to 3rd party page leaves `window.opener` exposed....
NA - CVE-2025-26058 - Webkul QloApps v1.6.1 exposes authentication...
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens...
NA - CVE-2025-26620 - Duende.AccessTokenManagement is a set of .NET...
Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.AccessTokenManagement contains a race condition when requesting access tokens...
Medium - CVE-2024-45774 - A flaw was found in grub2. A specially crafted...
A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The...
NA - CVE-2024-57055 - Server-Side Access Control Bypass vulnerability...
Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potentially call certain services without the necessary access level. This issue is...
NA - CVE-2024-57056 - Incorrect cookie session handling in...
Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to system logs and could be used by a malicious attacker to impersonate an existing...
NA - CVE-2025-21608 - Meshtastic is an open source mesh networking...
Meshtastic is an open source mesh networking solution. In affected firmware versions crafted packets over MQTT are able to appear as a DM in client to a node even though they were not decoded with...