High - CVE-2025-4040 - Authorization Bypass Through User-Controlled...
Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Privilege Escalation.This issue affects Automatic Station Monitoring System:...
Medium - CVE-2025-7925 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Banquet Booking System 1.0. Affected by this issue is some unknown functionality of the file...
NA - CVE-2024-13973 - A post-auth SQL injection vulnerability in...
A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.
NA - CVE-2024-13974 - A business logic vulnerability in the Up2Date...
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote...
High - CVE-2025-4129 - Authorization Bypass Through User-Controlled...
Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers.This issue affects PAVO Pay: before 13.05.2025.
High - CVE-2025-4130 - Use of Hard-coded Credentials vulnerability in...
Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.
NA - CVE-2025-6235 - In ExtremeControl before 25.5.12, a cross-site...
In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied...
NA - CVE-2025-6704 - An arbitrary file writing vulnerability in the...
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific...
NA - CVE-2025-7382 - A command injection vulnerability in WebAdmin...
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA)...
NA - CVE-2025-7624 - An SQL injection vulnerability in the legacy...
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active...