NA - CVE-2024-56901 - A Cross-Site Request Forgery (CSRF) in the...
A Cross-Site Request Forgery (CSRF) in the Account Management component of Geovision GV-ASWeb version 6.1.1.0 or less allows attackers to arbitrarily create Admin accounts via a crafted GET request...
NA - CVE-2024-56902 - An issue in Geovision GV-ASWeb with version...
An issue in Geovision GV-ASWeb with version 6.1.0.0 or less allows unauthorized attackers with low-level privileges to be able to request information about other accounts via a crafted HTTP request.
NA - CVE-2024-56903 - A Cross-Site Request Forgery (CSRF) in...
A Cross-Site Request Forgery (CSRF) in Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to execute arbitrary operations via supplying a crafted HTTP request.
NA - CVE-2025-24370 - Django-Unicorn adds modern reactive component...
Django-Unicorn adds modern reactive component functionality to Django templates. Affected versions of Django-Unicorn are vulnerable to python class pollution vulnerability. The vulnerability arises...
NA - CVE-2025-24899 - reNgine is an automated reconnaissance...
reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Penetration Tester,...
NA - CVE-2025-24959 - zx is a tool for writing better scripts. An...
zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended environment variables into `process.env`. This can lead to arbitrary command...
NA - CVE-2025-24960 - Jellystat is a free and open source Statistics...
Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user input in the route(s). This can lead to Path Traversal Vulnerabilities....
NA - CVE-2025-24961 - org.gaul S3Proxy implements the S3 API and...
org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backends could unintentionally expose local files to users. This issue has been...