NA - CVE-2025-25065 - SSRF vulnerability in the RSS feed parser in...
SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.
NA - CVE-2025-25181 - A SQL injection vulnerability in...
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL commands via the PmSess1 parameter.
NA - CVE-2023-52163 - Digiever DS-2105 Pro 3.1.0.71-11 devices allow...
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
NA - CVE-2023-52164 - access_device.cgi on Digiever DS-2105 Pro...
access_device.cgi on Digiever DS-2105 Pro 3.1.0.71-11 devices allows arbitrary file read. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
NA - CVE-2024-34896 - An issue in Nedis SmartLife Video Doorbell...
An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access...
NA - CVE-2024-44449 - Cross Site Scripting vulnerability in Quorum...
Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive information via the msg parameter in the Login page.
NA - CVE-2024-56898 - Incorrect access control in Geovision GV-ASWeb...
Incorrect access control in Geovision GV-ASWeb version 6.1.0.0 or less allows unauthorized attackers with low-level privileges to manage and create new user accounts via supplying a crafted HTTP...