NA - CVE-2025-25179 - Software installed and run as a non-privileged...
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.
NA - CVE-2025-49113 - Roundcube Webmail before 1.5.10 and 1.6.x...
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in...
Medium - CVE-2025-5429 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in juzaweb CMS up to 3.4.2. This vulnerability affects unknown code of the file /admin-cp/plugin/install of the component Plugins Page. The...
Medium - CVE-2025-5430 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in AssamLook CMS 1.0. This issue affects some unknown processing of the file /product.php. The manipulation of the argument ID...
NA - CVE-2025-1485 - The Real Cookie Banner: GDPR & ePrivacy Cookie...
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent WordPress plugin before 5.1.6, real-cookie-banner-pro WordPress plugin before 5.1.6 does not sanitise and escape some of its settings, which...
NA - CVE-2025-3951 - The WP-Optimize WordPress plugin before 4.2.0...
The WP-Optimize WordPress plugin before 4.2.0 does not properly escape user input when checking image compression statuses, which could allow users with the administrator role to conduct SQL...
Medium - CVE-2025-5431 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in AssamLook CMS 1.0. Affected is an unknown function of the file /department-profile.php. The manipulation of the argument ID leads to...
Medium - CVE-2025-5432 - A vulnerability has been found in AssamLook CMS...
A vulnerability has been found in AssamLook CMS 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /view_tender.php. The manipulation of the...
Medium - CVE-2025-1235 - A low privileged attacker can set the date of...
A low privileged attacker can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes the date of the switch to be set back to January 1st, 1970.