NA - CVE-2025-27403 - Ratify is a verification engine as a binary...
Ratify is a verification engine as a binary executable and on Kubernetes which enables verification of artifact security metadata and admits for deployment only those that comply with policies the...
NA - CVE-2025-25680 - LSC Smart Connect LSC Indoor PTZ Camera 7.6.32...
LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution...
NA - CVE-2025-25747 - Cross Site Scripting vulnerability in...
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the...
NA - CVE-2025-27601 - Umbraco is a free and open source .NET content...
Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3,...
NA - CVE-2025-27602 - Umbraco is a free and open source .NET content...
Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffice API URLs,...
NA - CVE-2025-27617 - Pimcore is an open source data and experience...
Pimcore is an open source data and experience management platform. Prior to version 11.5.4, authenticated users can craft a filter string used to cause a SQL injection. Version 11.5.4 fixes the issue.
Medium - CVE-2024-56338 - IBM Sterling B2B Integrator Standard Edition...
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed...
NA - CVE-2024-9157 - ** UNSUPPORTED WHEN ASSIGNED **
A privilege...
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a...
NA - CVE-2025-0149 - Insufficient verification of data authenticity...
Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access.
High - CVE-2025-21169 - Substance3D - Designer versions 14.1 and...
Substance3D - Designer versions 14.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user....