Medium - CVE-2024-56470 - IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is...
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially...
Medium - CVE-2024-56471 - IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is...
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially...
Medium - CVE-2024-56472 - IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is...
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus...
Medium - CVE-2024-56473 - IBM Aspera Shares 1.9.0 through 1.10.0 PL6...
IBM Aspera Shares 1.9.0 through 1.10.0 PL6 could allow an attacker to spoof their IP address, which is written to log files, due to improper verification of 'Client-IP' headers.
NA - CVE-2025-1003 - A potential vulnerability has been identified...
A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass which may result in escalation of privilege. HP is releasing a software...
NA - CVE-2025-22475 - Dell PowerProtect DD, versions prior to DDOS...
Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementation vulnerability. A remote attacker could...
NA - CVE-2025-24982 - Cross-site request forgery vulnerability exists...
Cross-site request forgery vulnerability exists in Activity Log WinterLock versions prior to 1.2.5. If a user views a malicious page while logged in, the log data may be deleted.
NA - CVE-2024-13114 - The WP Projects Portfolio with Client...
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site...
NA - CVE-2024-13115 - The WP Projects Portfolio with Client...
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers...
NA - CVE-2024-13325 - The Glossy WordPress plugin through 2.3.5 does...
The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...