NA - CVE-2025-54137 - HAX CMS NodeJS allows users to manage their...
HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were distributed with hardcoded default credentials for the user and superuser...
NA - CVE-2025-54138 - LibreNMS is an auto-discovering PHP/MySQL/SNMP...
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. LibreNMS versions 25.6.0 and below contain...
NA - CVE-2025-54140 - pyLoad is a free and open-source Download...
pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated path traversal vulnerability exists in the /json/upload endpoint of pyLoad. By...
NA - CVE-2025-54141 - ViewVC is a browser interface for CVS and...
ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the standalone.py script provided in the ViewVC...
NA - CVE-2025-7766 - Lantronix Provisioning Manager is vulnerable to...
Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with...
NA - CVE-2025-8010 - Type Confusion in V8 in Google Chrome prior to...
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
NA - CVE-2025-8011 - Type Confusion in V8 in Google Chrome prior to...
Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
NA - CVE-2025-43020 - A potential command
injection vulnerability has...
A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input....
NA - CVE-2025-43021 - A potential security
vulnerability has been...
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has...
NA - CVE-2025-43022 - A potential SQL injection vulnerability has...
A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP...