High - CVE-2025-2088 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0. Affected is an unknown function of the file /admin/profile.php. The manipulation...
NA - CVE-2025-2089 - A vulnerability has been found in StarSea99...
A vulnerability has been found in StarSea99 starsea-mall 1.0/2.X and classified as critical. Affected by this vulnerability is the function updateUserInfo of the file /personal/updateInfo of the...
NA - CVE-2025-2090 - A vulnerability was found in PHPGurukul...
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php of the...
NA - CVE-2025-27152 - axios is a promise based HTTP client for the...
axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ?baseURL is set, axios sends the...
NA - CVE-2025-27518 - Cognita is a RAG (Retrieval Augmented...
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend...
NA - CVE-2025-27519 - Cognita is a RAG (Retrieval Augmented...
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. A path traversal issue exists at...
NA - CVE-2025-27597 - Vue I18n is the internationalization plugin for...
Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An...
NA - CVE-2025-27603 - XWiki Confluence Migrator Pro helps admins to...
XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped...
Medium - CVE-2023-35894 - IBM Control Center 6.2.1 through 6.3.1 is...
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks...