NA - CVE-2025-1076 - A Stored Cross-Site Scripting (Stored XSS)...
A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable...
NA - CVE-2022-31764 - The Lite UI of Apache ShardingSphere...
The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI...
NA - CVE-2023-5878 - Honeywell OneWireless
Wireless Device Manager...
Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who...
NA - CVE-2024-43811 - Rejected reason: ** REJECT ** DO NOT USE THIS...
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2024....
NA - CVE-2025-0994 - Trimble Cityworks versions prior to 15.8.9 and...
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to...
NA - CVE-2022-40490 - Tiny File Manager v2.4.7 and below was...
Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected...
NA - CVE-2024-13614 - Kaspersky has fixed a security issue in...
Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office...
NA - CVE-2024-39033 - In Newgensoft OmniDocs 11.0_SP1_03_006,...
In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.
NA - CVE-2024-39272 - A cross-site scripting (xss) vulnerability...
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code....