NA - CVE-2025-6725 - In the PdfViewer component, a Cross-Site...
In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has already been loaded and the user engages with a tool that requires the DOM to...
Medium - CVE-2025-20308 - A vulnerability in Cisco Spaces Connector could...
A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. This...
Medium - CVE-2025-20310 - A vulnerability in the web UI of Cisco...
A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the...
NA - CVE-2025-52886 - Poppler is a PDF rendering library. Versions...
Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count...
NA - CVE-2025-53358 - kotaemon is an open-source RAG-based tool for...
kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/index/file/ui.py, the index_fn method accepts both URLs and local file paths...
NA - CVE-2025-53359 - ethereum is a common ethereum structs for Rust....
ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EIP-2) was only checked for "legacy" transactions, but not for EIP-2930,...
NA - CVE-2025-6942 - The distributed engine of Secret Server...
The distributed engine of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attacker to impersonate another distributed engine.
NA - CVE-2025-6943 - Secret Server version 11.7 and earlier is...
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.
Medium - CVE-2025-20307 - A vulnerability in the web-based management...
A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an authenticated, remote attacker to to conduct cross-site scripting (XSS)...
Critical - CVE-2025-20309 - A vulnerability in Cisco Unified Communications...
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote...