High - CVE-2025-2705 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument File...
NA - CVE-2025-0255 - HCL DevOps Deploy / HCL Launch could allow a...
HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
NA - CVE-2025-29778 - Kyverno is a policy engine designed for cloud...
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign...
NA - CVE-2025-30112 - On 70mai Dash Cam 1S devices, by connecting...
On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorization mechanism...
NA - CVE-2025-30205 - kanidim-provision is a helper utility that uses...
kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in the (optional) kanidm...
NA - CVE-2025-30208 - Vite, a provider of frontend development...
Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list....
NA - CVE-2025-22223 - Spring Security 6.4.0 - 6.4.3 may not correctly...
Spring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an authorization bypass. You are not affected if you are not...
Medium - CVE-2025-2706 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. The manipulation of...
Medium - CVE-2025-2707 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functionality of the file /app-api/infra/file/upload...
NA - CVE-2025-2746 - An authentication bypass vulnerability in...
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication....