NA - CVE-2025-44654 - In Linksys E2500 3.0.04.002, the...
In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the...
NA - CVE-2025-52575 - EspoCRM is an Open Source CRM (Customer...
EspoCRM is an Open Source CRM (Customer Relationship Management) software. EspoCRM versions 9.1.6 and earlier are vulnerable to blind LDAP Injection when LDAP authentication is enabled. A remote,...
High - CVE-2025-7933 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/settings_update.php of the component Setting...
NA - CVE-2020-26799 - A reflected cross-site scripting (XSS)...
A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data.
Medium - CVE-2025-36057 - IBM Cognos Analytics Mobile (iOS) 1.1.0 through...
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 is vulnerable to authentication bypass by using the Local Authentication Framework library which is not needed as biometric authentication...
Medium - CVE-2025-36106 - IBM Cognos Analytics Mobile (iOS) 1.1.0 through...
IBM Cognos Analytics Mobile (iOS) 1.1.0 through 1.1.22 could allow malicious actors to view and modify information coming to and from the application which could then be used to access confidential...
NA - CVE-2025-51396 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username...
NA - CVE-2025-51397 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload...