NA - CVE-2025-45661 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in miniTCG v1.3.1 beta allows attackers to execute abritrary web scripts or HTML via injecting a crafted payload into the id parameter at /members/edit.php.
NA - CVE-2025-45784 - D-Link DPH-400S/SE VoIP Phone v1.01 contains...
D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware...
NA - CVE-2025-49015 - The Couchbase .NET SDK (client library) before...
The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a...
NA - CVE-2025-6240 - Improper Input Validation vulnerability in...
Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authentication to the Profisee system.This issue affects Profisee: from 2020R1 before...
Medium - CVE-2024-54183 - IBM Sterling B2B Integrator and IBM Sterling...
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user...
High - CVE-2025-36048 - IBM webMethods Integration Server 10.5, 10.7,...
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privileges when handling external entities due to execution with unnecessary privileges.
High - CVE-2025-36049 - IBM webMethods Integration Server 10.5, 10.7,...
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could...