High - CVE-2025-6111 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the...
Critical - CVE-2025-6169 - The WIMP website co-construction management...
The WIMP website co-construction management platform from HAMASTAR Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read,...
High - CVE-2025-6112 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the...
High - CVE-2025-6113 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument...
NA - CVE-2025-2091 - An open redirection vulnerability in M-Files...
An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making...
NA - CVE-2025-3464 - A race condition vulnerability exists in...
A race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially leading to authentication bypass. Refer to the 'Security...
NA - CVE-2025-40726 - Reflected Cross-Site Scripting (XSS)...
Reflected Cross-Site Scripting (XSS) vulnerability in /pages/search-results-page in Nosto, which allows remote attackers to execute arbitrary code via the q GET request parameter.
NA - CVE-2025-40727 - A Reflected Cross Site Scripting (XSS)...
A Reflected Cross Site Scripting (XSS) vulnerability was found in '/search' in Phoenix Site CMS from Phoenix, which allows remote attackers to execute arbitrary code via 's' GET...
NA - CVE-2025-40728 - SQL injection vulnerability in Customer Support...
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the...