NA - CVE-2025-40659 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to...
NA - CVE-2025-40660 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to...
NA - CVE-2025-40661 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to...
NA - CVE-2025-40662 - Absolute path disclosure vulnerability in DM...
Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigating to a non-existent file.
NA - CVE-2024-13089 - An OS command injection vulnerability within...
An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS commands. Users with administrative privileges...
NA - CVE-2024-13090 - A privilege escalation vulnerability may enable...
A privilege escalation vulnerability may enable a service account to elevate its privileges. The sudo rules configured for a local service account were excessively permissive, potentially...
Medium - CVE-2025-41657 - Due to an undocumented active bluetooth stack...
Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker.
Medium - CVE-2025-2918 - The Ultimate Blocks – WordPress Blocks Plugin...
The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.3.3 due to insufficient...
NA - CVE-2025-43697 - Improper Preservation of Permissions...
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025
NA - CVE-2025-43698 - Improper Preservation of Permissions...
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. This impacts OmniStudio: before...