NA - CVE-2025-25967 - Acora CMS version 10.1.1 is vulnerable to...
Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion...
NA - CVE-2025-27499 - WeGIA is an open source Web Manager for...
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the processa_edicao_socio.php...
NA - CVE-2025-27500 - OpenZiti is a free and open source project...
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) on the admin panel can be accessed without any form of authentication. This...
NA - CVE-2025-27501 - OpenZiti is a free and open source project...
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form of authentication. This endpoint...
Medium - CVE-2024-10904 - There is a stored Cross-site Scripting...
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked...
Medium - CVE-2024-51942 - There is a stored Cross-site Scripting...
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked...
Medium - CVE-2024-51944 - There is a stored Cross-site Scripting...
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked...
Medium - CVE-2024-51945 - There is a stored Cross-site Scripting...
There is a stored Cross-site Scripting vulnerability in ArcGIS Server for versions 10.9.1 – 11.3 that may allow a remote, authenticated attacker to create a stored crafted link which when clicked...