Medium - CVE-2025-2150 - The C&Cm@il from HGiga has a Stored Cross-Site...
The C&Cm@il from HGiga has a Stored Cross-Site Scripting (XSS) vulnerability, allowing remote attackers with regular privileges to send emails containing malicious JavaScript code, which will be...
NA - CVE-2025-27253 - An improper input validation in GE Vernova UR...
An improper input validation in GE Vernova UR IED family devices from version 7.0 up to 8.60 allows an attacker to provide input that enstablishes a TCP connection through a port forwarding. The...
NA - CVE-2025-27254 - Improper Authentication vulnerability in GE...
Improper Authentication vulnerability in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry...
NA - CVE-2025-27255 - Use of Hard-coded Credentials vulnerability in...
Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker...
NA - CVE-2025-27256 - Missing Authentication for Critical Function...
Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client...
NA - CVE-2025-27257 - Insufficient Verification of Data Authenticity...
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is...
NA - CVE-2024-13918 - The Laravel framework versions between 11.9.0...
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.
NA - CVE-2024-13919 - The Laravel framework versions between 11.9.0...
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page.
NA - CVE-2025-24387 - A vulnerability in OTRS Application Server...
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A request to an OTRS endpoint from a possible...
Medium - CVE-2025-2147 - A vulnerability was found in Beijing Zhide...
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown...