NA - CVE-2025-2271 - A vulnerability exists in Issuetrak v17.2.2 and...
A vulnerability exists in Issuetrak v17.2.2 and prior that allows a low-privileged user to access audit results of other users by exploiting an Insecure Direct Object Reference (IDOR) vulnerability...
Medium - CVE-2025-1785 - The Download Manager plugin for WordPress is...
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' action. This makes it possible for...
High - CVE-2025-25175 - A vulnerability has been identified in...
A vulnerability has been identified in Simcenter Femap V2401 (All versions < V2401.0003), Simcenter Femap V2406 (All versions < V2406.0002). The affected application contains a memory corruption...
NA - CVE-2025-21104 - Dell NetWorker, 19.11.0.3 and below versions,...
Dell NetWorker, 19.11.0.3 and below versions, contain(s) an Open Redirect Vulnerability in NMC. An unauthenticated attacker with remoter access could potentially exploit this vulnerability, leading...
NA - CVE-2025-29994 - This vulnerability exists in the CAP back...
This vulnerability exists in the CAP back office application due to improper authentication check at the API endpoint. An unauthenticated remote attacker with a valid login ID could exploit this...
NA - CVE-2025-29995 - This vulnerability exists in the CAP back...
This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API endpoints. An authenticated remote attacker with a valid login ID could...
NA - CVE-2025-29996 - This vulnerability exists in the CAP back...
This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanism in its API based login. A remote attacker with valid credentials could...
NA - CVE-2025-29997 - This vulnerability exists in the CAP back...
This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by...
NA - CVE-2025-29998 - This vulnerability exists in the CAP back...
This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by...