NA - CVE-2025-26742 - Improper Neutralization of Input During Web...
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo allows Stored XSS.This issue affects Gallery for...
NA - CVE-2025-27147 - The GLPI Inventory Plugin handles various types...
The GLPI Inventory Plugin handles various types of tasks for GLPI agents, including network discovery and inventory (SNMP), software deployment, VMWare ESX host remote inventory, and data...
NA - CVE-2025-30212 - Frappe is a full-stack web application...
Frappe is a full-stack web application framework. An SQL Injection vulnerability has been identified in Frappe Framework prior to versions 14.89.0 and 15.51.0 which could allow a malicious actor to...
NA - CVE-2025-30213 - Frappe is a full-stack web application...
Frappe is a full-stack web application framework. Prior to versions 14.91.0 and 15.52.0, a system user was able to create certain documents in a specific way that could lead to remote code...
NA - CVE-2025-30214 - Frappe is a full-stack web application...
Frappe is a full-stack web application framework. Prior to versions 14.89.0 and 15.51.0, making crafted requests could lead to information disclosure that could further lead to account takeover....
NA - CVE-2024-58104 - A vulnerability in the Trend Micro Apex One...
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected...
NA - CVE-2024-58105 - A vulnerability in the Trend Micro Apex One...
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected...