NA - CVE-2025-48941 - MyBB is free and open source forum software....
MyBB is free and open source forum software. Prior to version 1.8.39, the search component does not validate permissions correctly, which allows attackers to determine the existence of hidden...
NA - CVE-2024-1440 - An open redirection vulnerability exists in...
An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A...
NA - CVE-2024-3509 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability exists in the Management Console of multiple WSO2 products due to insufficient input validation in the Rich Text Editor within the registry...
NA - CVE-2024-7073 - A server-side request forgery (SSRF)...
A server-side request forgery (SSRF) vulnerability exists in multiple WSO2 products due to improper input validation in SOAP admin services. This flaw allows unauthenticated attackers to manipulate...
NA - CVE-2024-7074 - An arbitrary file upload vulnerability exists...
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user input in SOAP admin services. A malicious actor with administrative privileges can upload...
NA - CVE-2024-8008 - A reflected cross-site scripting (XSS)...
A reflected cross-site scripting (XSS) vulnerability exists in multiple [Vendor Name] products due to insufficient output encoding in error messages generated by the JDBC user store connection...
NA - CVE-2025-48994 - SignXML is an implementation of the W3C XML...
SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set...
NA - CVE-2025-48995 - SignXML is an implementation of the W3C XML...
SignXML is an implementation of the W3C XML Signature standard in Python. When verifying signatures with X509 certificate validation turned off and HMAC shared secret set...
High - CVE-2025-5036 - A maliciously crafted RFA file, when linked or...
A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read...
Medium - CVE-2025-20297 - In Splunk Enterprise versions below 9.4.2,...
In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not hold the...