NA - CVE-2025-24899 - reNgine is an automated reconnaissance...
reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Penetration Tester,...
NA - CVE-2025-24959 - zx is a tool for writing better scripts. An...
zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended environment variables into `process.env`. This can lead to arbitrary command...
NA - CVE-2025-24960 - Jellystat is a free and open source Statistics...
Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user input in the route(s). This can lead to Path Traversal Vulnerabilities....
NA - CVE-2025-24961 - org.gaul S3Proxy implements the S3 API and...
org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to users. This issue has been...
NA - CVE-2025-24962 - reNgine is an automated reconnaissance...
reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in commit...
NA - CVE-2024-35177 - Wazuh is a free and open source platform used...
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based...
NA - CVE-2024-47770 - Wazuh is a free and open source platform used...
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based...
NA - CVE-2025-22129 - Tuleap is an Open Source Suite to improve...
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In affected versions an unauthorized user might get access to restricted information. This issue has...
NA - CVE-2025-23210 - phpoffice/phpspreadsheet is a pure PHP library...
phpoffice/phpspreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions have been found to have a Bypass of the Cross-site Scripting (XSS) sanitizer using the...
NA - CVE-2025-24029 - Tuleap is an Open Source Suite to improve...
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users (possibly anonymous ones if the widget is used in the dashboard of a public project) might get...