NA - CVE-2025-27412 - REDAXO is a PHP-based CMS. In Redaxo from 5.0.0...
REDAXO is a PHP-based CMS. In Redaxo from 5.0.0 through 5.18.2, the rex-api-result parameter is vulnerable to Reflected cross-site scripting (XSS) on the page of AddOns. This vulnerability is fixed...
NA - CVE-2025-27497 - OpenDJ is an LDAPv3 compliant directory...
OpenDJ is an LDAPv3 compliant directory service. OpenDJ prior to 4.9.3 contains a denial-of-service (DoS) vulnerability that causes the server to become unresponsive to all LDAP requests without...
NA - CVE-2024-11035 - Carbon Black Cloud Windows Sensor, prior to...
Carbon Black Cloud Windows Sensor, prior to 4.0.3, may be susceptible to an Information Leak vulnerability, which s a type of issue whereby sensitive information may b exposed due to a...
High - CVE-2025-20206 - A vulnerability in the interprocess...
A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected...
Medium - CVE-2025-20208 - A vulnerability in the web-based management...
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow a low-privileged, remote attacker to conduct a cross-site scripting (XSS) attack...
NA - CVE-2024-31525 - Peppermint Ticket Management 0.4.6 is...
Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the...
NA - CVE-2025-27513 - OpenTelemetry dotnet is a dotnet telemetry...
OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (DoS) when a tracestate and traceparent header is...
NA - CVE-2025-27515 - Laravel is a web application framework. When...
Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation...