High - CVE-2024-52902 - IBM Cognos Controller 11.0.0 through 11.0.1 FP3...
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the...
Medium - CVE-2024-28776 - IBM Cognos Controller 11.0.0 through 11.0.1 FP3...
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI...
High - CVE-2024-28777 - IBM Cognos Controller 11.0.0 through 11.0.1 FP3...
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate...
Medium - CVE-2024-28780 - IBM Cognos Controller 11.0.0 through 11.0.1 FP3...
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly...
Medium - CVE-2024-45081 - IBM Cognos Controller 11.0.0 through 11.0.1 FP3...
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to incorrect authorization checks.
High - CVE-2024-45084 - IBM Cognos Controller 11.0.0 through 11.0.1 FP3...
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. An attacker could execute arbitrary commands on the...
Medium - CVE-2025-1465 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. The manipulation leads to code...
Medium - CVE-2025-20153 - A vulnerability in the email filtering...
A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been...
Medium - CVE-2025-20158 - A vulnerability in the debug shell of Cisco...
A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticated, local attacker to access sensitive information on an affected device. To...