NA - CVE-2024-49364 - tiny-secp256k1 is a tiny secp256k1 native/JS...
tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a private key can be extracted on signing a malicious JSON-stringifiable object, when global Buffer is the buffer...
NA - CVE-2024-49365 - tiny-secp256k1 is a tiny secp256k1 native/JS...
tiny-secp256k1 is a tiny secp256k1 native/JS wrapper. Prior to version 1.1.7, a malicious JSON-stringifyable message can be made passing on verify(), when global Buffer is the buffer package. This...
High - CVE-2025-6939 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteSurvey of the component HTTP POST...
High - CVE-2025-6940 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability is an unknown functionality of the file /boafrm/formParentControl of the...
NA - CVE-2025-5967 - A stored cross-site scripting vulnerability in...
A stored cross-site scripting vulnerability in ENS HX 10.0.4 allows a malicious user to inject arbitrary HTML into the ENS HX Malware Scan Name field, resulting in the exposure of sensitive data.
NA - CVE-2025-6081 - Insufficiently Protected Credentials in LDAP in...
Insufficiently Protected Credentials in LDAP in Konica Minolta bizhub 227 Multifunction printers version GCQ-Y3 or earlier allows an attacker can reconfigure the target device to use an external...
Critical - CVE-2025-6934 - The Opal Estate Pro – Property Management and...
The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all...
Critical - CVE-2025-41648 - An unauthenticated remote attacker can bypass...
An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to access and change all available settings of the IndustrialPI.
Critical - CVE-2025-41656 - An unauthenticated remote attacker can run...
An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.