NA - CVE-2025-29410 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the component /contact.php of Hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload...
NA - CVE-2025-29412 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted...
NA - CVE-2024-48591 - Inflectra SpiraTeam 7.2.00 is vulnerable to...
Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing.
NA - CVE-2025-29411 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Medium - CVE-2025-2546 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in D-Link DIR-618 and DIR-605L 2.02/3.02. This vulnerability affects unknown code of the file /goform/formAdvFirewall of the component Firewall...
NA - CVE-2025-25758 - An issue in KukuFM Android v1.12.7 (11207)...
An issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdroidManifest.xml
NA - CVE-2025-2538 - A specific type of ArcGIS Enterprise deployment...
A specific type of ArcGIS Enterprise deployment is vulnerable to a Password Recovery Exploitation vulnerability in Portal that could allow an attacker to reset the password on the built in-admin...