NA - CVE-2025-30940 - Improper Neutralization of Input During Web...
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in melipayamak Melipayamak allows Stored XSS. This issue affects Melipayamak: from n/a...
Medium - CVE-2025-0620 - A flaw was found in Samba. The smbd service...
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients...
NA - CVE-2025-38001 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice Savino says: "We are writing to report that this...
NA - CVE-2025-38002 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo() Not everything requires locking in there, which is why the...
High - CVE-2025-5778 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. Affected is an unknown function of the file /adminSQL. The manipulation of the...
High - CVE-2025-5791 - A flaw was found in the user's crate for...
A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to...
NA - CVE-2025-5806 - Jenkins Gatling Plugin 136.vb_9009b_3d33a_e...
Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site...
NA - CVE-2025-27531 - Deserialization of Untrusted Data vulnerability...
Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary...
Critical - CVE-2025-41646 - An unauthorized remote attacker can bypass the...
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device
Medium - CVE-2025-5779 - A vulnerability has been found in code-projects...
A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file...