NA - CVE-2025-27137 - Dependency-Track is a component analysis...
Dependency-Track is a component analysis platform that allows organizations to identify and reduce risk in the software supply chain. Dependency-Track allows users with the `SYSTEM_CONFIGURATION`...
NA - CVE-2025-27140 - WeGIA is a Web manager for charitable...
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This...
NA - CVE-2025-27141 - Metabase Enterprise Edition is the enterprise...
Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51.14, 1.52.11, and...
NA - CVE-2024-53542 - Incorrect access control in the component...
Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the...
NA - CVE-2024-53543 - NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time...
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.
NA - CVE-2024-53544 - NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time...
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.
NA - CVE-2024-56525 - In Public Knowledge Project (PKP) OJS, OMP, and...
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context,...