NA - CVE-2025-1888 - The Leica Web Viewer within the Aperio Eslide...
The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS). An authenticated user can access the slides within a project and injecting...
NA - CVE-2025-26215 - Rejected reason: DO NOT USE THIS CANDIDATE...
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
NA - CVE-2025-26216 - Rejected reason: DO NOT USE THIS CANDIDATE...
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
NA - CVE-2025-27606 - Element Android is an Android Matrix Client...
Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user if they input the wrong PIN more than...
NA - CVE-2025-29384 - In Tenda AC9 v1.0 V15.03.05.14_multi, the...
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
NA - CVE-2025-29385 - In Tenda AC9 v1.0 V15.03.05.14_multi, the...
In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
NA - CVE-2025-29386 - In Tenda AC9 v1.0 V15.03.05.14_multi, the mac...
In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
NA - CVE-2025-29387 - In Tenda AC9 v1.0 V15.03.05.14_multi, the...
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
NA - CVE-2025-29774 - xml-crypto is an XML digital signature and...
xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.0.1, 3.2.1, and 2.1.6 to bypass authentication...
NA - CVE-2024-12019 - The API used to interact with documents in the...
The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on the underlying operating system. An account with...