NA - CVE-2025-26373 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (user endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to...
NA - CVE-2025-26374 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua (users endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to...
NA - CVE-2025-26375 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to create users with...
NA - CVE-2025-26376 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to modify user data via...
NA - CVE-2025-26377 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to remove users via crafted...
NA - CVE-2025-26378 - A CWE-862 "Missing Authorization" in...
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to reset passwords,...
NA - CVE-2024-12251 - In Progress® Telerik® UI for WinUI versions...
In Progress® Telerik® UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.
NA - CVE-2024-12379 - A denial of service vulnerability in GitLab...
A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of...
NA - CVE-2024-54160 - dashboards-reporting (aka Dashboards Reports)...
dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer.
NA - CVE-2025-0376 - An XSS vulnerability exists in GitLab CE/EE...
An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions...