NA - CVE-2024-13915 - Android based smartphones from vendors such as...
Android based smartphones from vendors such as Ulefone and Krüger&Matz contain "com.pri.factorytest" application preloaded onto devices during manufacturing process. The application...
NA - CVE-2024-13916 - An application "com.pri.applock", which is...
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed...
NA - CVE-2024-13917 - An application "com.pri.applock", which is...
An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed...
NA - CVE-2024-23589 - Due to outdated Hash algorithm, HCL Glovius...
Due to outdated Hash algorithm, HCL Glovius Cloud could allow attackers to guess the input data using brute-force or dictionary attacks efficiently using modern hardware such as GPUs or ASICs
NA - CVE-2024-42190 - HCL Traveler for Microsoft Outlook (HTMO) is...
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
NA - CVE-2024-42191 - HCL Traveler for Microsoft Outlook (HTMO) is...
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
High - CVE-2025-5356 - A vulnerability was found in FreeFloat FTP...
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown function of the component BYE Command Handler. The manipulation leads to buffer...
Medium - CVE-2025-5142 - The Simple Page Access Restriction plugin for...
The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and...
Medium - CVE-2025-5235 - The OpenSheetMusicDisplay plugin for WordPress...
The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.4.0 due to insufficient input...
NA - CVE-2025-1763 - An issue has been discovered in GitLab EE that...
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions...