NA - CVE-2025-46001 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
NA - CVE-2025-46002 - An issue in Filemanager v2.5.0 and below allows...
An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.
Medium - CVE-2025-7784 - A flaw was found in the Keycloak identity and...
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their...
Low - CVE-2025-7786 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the file /bbs/scrap_popin_update/qa/ of the component...
NA - CVE-2025-46000 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG...
NA - CVE-2025-46732 - OpenCTI is an open source platform for managing...
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnerability in the GrapQL...