NA - CVE-2025-41404 - Direct request ('Forced Browsing')...
Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can...
NA - CVE-2025-48497 - Cross-site request forgery vulnerability exists...
Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary...
NA - CVE-2025-5315 - An issue has been discovered in GitLab CE/EE...
An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role...
NA - CVE-2025-5846 - An issue has been discovered in GitLab EE...
An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to assign...
NA - CVE-2025-5459 - A user with specific node group editing...
A user with specific node group editing permissions and a specially crafted class parameter could be used to execute commands as root on the primary host. It affects Puppet Enterprise versions...
NA - CVE-2024-11584 - cloud-init through 25.1.2 includes the systemd...
cloud-init through 25.1.2 includes the systemd socket unit cloud-init-hotplugd.socket with default SocketMode that grants 0666 permissions, making it world-writable. This being used for the...
NA - CVE-2024-6174 - When a non-x86 platform is detected, cloud-init...
When a non-x86 platform is detected, cloud-init grants root access to a hardcoded url with a local IP address. To prevent this, cloud-init default configurations disable platform enumeration.
Medium - CVE-2025-5338 - The Royal Elementor Addons plugin for WordPress...
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.7.1024 due to insufficient input...
Medium - CVE-2025-5842 - The Modern Design Library plugin for WordPress...
The Modern Design Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.1.4 due to insufficient input...