NA - CVE-2025-34142 - An XML External Entity (XXE) injection...
An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication handler processes XML...
NA - CVE-2025-34143 - An authentication bypass vulnerability exists...
An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal SYSTEM user by manipulating the username field....
NA - CVE-2015-10140 - The Ajax Load More plugin before 2.8.1.2 does...
The Ajax Load More plugin before 2.8.1.2 does not have authorisation in some of its AJAX actions, allowing any authenticated users, such as subscriber, to upload and delete arbitrary files.
Medium - CVE-2025-4294 - Improper Neutralization of Input During Web...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HotelRunner B2B allows Cross-Site Scripting (XSS).This issue affects B2B:...
Medium - CVE-2025-4295 - Improper Validation of Certificate with Host...
Improper Validation of Certificate with Host Mismatch vulnerability in HotelRunner B2B allows HTTP Response Splitting.This issue affects B2B: before 04.06.2025.
NA - CVE-2025-51867 - Insecure Direct Object Reference (IDOR)...
Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI (deepfiction.ai) thru June 3, 2025, allowing attackers to chat with the LLM using other users' credits via sensitive...
High - CVE-2025-8017 - A vulnerability was found in Tenda AC7...
A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSetMacFilterCfg of the file /goform/setMacFilterCfg of the component httpd. The...
Low - CVE-2025-4878 - A vulnerability was found in libssh, where an...
A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This flaw can be triggered if the file specified by the...
NA - CVE-2025-51858 - Self Cross-Site Scripting (XSS) vulnerability...
Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent...
NA - CVE-2025-51859 - Stored Cross-Site Scripting (XSS) vulnerability...
Stored Cross-Site Scripting (XSS) vulnerability in Chaindesk thru 2025-05-26 in its agent chat component. An attacker can achieve arbitrary client-side script execution by crafting an AI agent...