NA - CVE-2025-25772 - A Cross-Site Request Forgery (CSRF) in the...
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
High - CVE-2025-1555 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to...
NA - CVE-2025-25282 - RAGFlow is an open-source RAG...
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR)...
NA - CVE-2019-8900 - A vulnerability in the SecureROM of some Apple...
A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute arbitrary code upon booting those devices. This vulnerability allows...
NA - CVE-2025-26622 - vyper is a Pythonic Smart Contract Language for...
vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate square roots of decimals. Unfortunately, improper handling of the oscillating...
NA - CVE-2025-27104 - vyper is a Pythonic Smart Contract Language for...
vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a for loop. While the iterator expression cannot produce...
NA - CVE-2025-27105 - vyper is a Pythonic Smart Contract Language for...
vyper is a Pythonic Smart Contract Language for the EVM. Vyper handles AugAssign statements by first caching the target location to avoid double evaluation. However, in the case when target is an...
NA - CVE-2025-27106 - binance-trading-bot is an automated Binance...
binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-trading-bot can achieve Remote Code Execution on the host system due to a...
NA - CVE-2025-27108 - dom-expressions is a Fine-Grained Runtime for...
dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering. In affected versions the use of javascript's `.replace()` opens up to potential Cross-site Scripting (XSS)...
NA - CVE-2025-27109 - solid-js is a declarative, efficient, and...
solid-js is a declarative, efficient, and flexible JavaScript library for building user interfaces. In affected versions Inserts/JSX expressions inside illegal inlined JSX fragments lacked...