NA - CVE-2023-25610 - A buffer underwrite ('buffer...
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through...
NA - CVE-2024-9103 - Improper Neutralization of Script in Attributes...
Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messages module) allows Stored XSS. This issue affects Email Security through 8.5.5.
NA - CVE-2025-0256 - HCL DevOps Deploy / HCL Launch could allow an...
HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
NA - CVE-2025-23204 - API Platform Core is a system to create...
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another...
NA - CVE-2025-29294 - Rejected reason: DO NOT USE THIS CVE RECORD....
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
High - CVE-2025-2705 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload of the file /Api/FileUploadApi.ashx. The manipulation of the argument File...
NA - CVE-2025-0255 - HCL DevOps Deploy / HCL Launch could allow a...
HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
NA - CVE-2025-29778 - Kyverno is a policy engine designed for cloud...
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign...
NA - CVE-2025-30112 - On 70mai Dash Cam 1S devices, by connecting...
On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorization mechanism...
NA - CVE-2025-30205 - kanidim-provision is a helper utility that uses...
kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in the (optional) kanidm...