NA - CVE-2025-41437 - Zohocorp ManageEngine OpManager, NetFlow...
Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.
Medium - CVE-2025-5873 - A vulnerability was found in eCharge Hardy...
A vulnerability was found in eCharge Hardy Barth Salia PLCC 2.2.0. It has been declared as critical. This vulnerability affects unknown code of the file /firmware.php of the component Web UI. The...
Medium - CVE-2025-5874 - A vulnerability was found in Redash up to...
A vulnerability was found in Redash up to 10.1.0/25.1.0. It has been rated as critical. This issue affects the function run_query of the file /query_runner/python.py of the component getattr...
NA - CVE-2025-5875 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in TP-Link TL-IPC544EP-W4 1.0.9 Build 240428 Rel 69493n. Affected is the function sub_69064 of the file /bin/main. The manipulation of the...
NA - CVE-2025-5876 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in Lucky LM-520-SC, LM-520-FSC and LM-520-FSC-SAM up to 20250321. Affected by this vulnerability is an unknown functionality. The manipulation...
NA - CVE-2025-40668 - Incorrect authorization vulnerability in...
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a POST request using...
NA - CVE-2025-40669 - Incorrect authorization vulnerability in...
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including...
NA - CVE-2025-40670 - Incorrect authorization vulnerability in...
Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to...