NA - CVE-2025-52168 - Incorrect access control in the dynawebservice...
Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers to access arbitrary files on the system.
NA - CVE-2025-53901 - Wasmtime is a runtime for WebAssembly. Prior to...
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation of the WASIp1 set of import functions can lead to a WebAssembly guest...
High - CVE-2025-7795 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the function fromP2pListFilter of the file /goform/P2pListFilter. The...
High - CVE-2025-7796 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserAdd of the file /goform/PPTPDClient. The manipulation of the argument...
Medium - CVE-2025-7797 - A vulnerability was found in GPAC up to 2.4. It...
A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf_dash_download_init_segment of the file src/media_tools/dash_client.c. The...
Medium - CVE-2025-33014 - IBM Sterling B2B Integrator and IBM Sterling...
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web link with untrusted references to an external site. A remote attacker could...
NA - CVE-2025-52163 - A Server-Side Request Forgery (SSRF) in the...
A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to forcefully initiate connections to arbitrary...
NA - CVE-2025-54309 - CrushFTP 10 before 10.8.5 and 11 before...
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as...