NA - CVE-2025-34097 - An unrestricted file upload vulnerability...
An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of uploaded plugin archives. An attacker with administrative privileges can upload...
NA - CVE-2025-34098 - A path traversal vulnerability exists in...
A path traversal vulnerability exists in Riverbed SteelHead VCX appliances (confirmed in VCX255U 9.6.0a) due to improper input validation in the log filtering functionality exposed via the...
NA - CVE-2025-34099 - An unauthenticated command injection...
An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vicidial_sales_viewer.php component when password encryption is enabled (a...
NA - CVE-2025-34100 - An unrestricted file upload vulnerability...
An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to...
NA - CVE-2025-34101 - An unauthenticated command injection...
An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoint exposed by the console component (default...
NA - CVE-2025-34102 - A remote code execution vulnerability exists in...
A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploitation of SQL injection and command injection vulnerabilities. An...
NA - CVE-2025-45662 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attackers to execute arbitrary Javascript in the context of a user's browser...
NA - CVE-2025-53506 - Uncontrolled Resource Consumption vulnerability...
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This...
NA - CVE-2025-53628 - cpp-httplib is a C++11 single-file header-only...
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to...
NA - CVE-2025-53629 - cpp-httplib is a C++11 single-file header-only...
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily...