NA - CVE-2025-24287 - A vulnerability allowing local system users to...
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.
NA - CVE-2025-24288 - The Versa Director software exposes a number of...
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the...
NA - CVE-2025-24291 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability....
NA - CVE-2025-50181 - urllib3 is a user-friendly HTTP client library...
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that...
NA - CVE-2025-50182 - urllib3 is a user-friendly HTTP client library...
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the...
NA - CVE-2025-4661 - A path transversal vulnerability in
Brocade...
A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the...
NA - CVE-2025-50183 - OpenList Frontend is a UI component for...
OpenList Frontend is a UI component for OpenList. Prior to version 4.0.0-rc.4, a vulnerability exists in the file preview/browsing feature of the application, where files with a .py extension that...
NA - CVE-2025-52467 - pgai is a Python library that transforms...
pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to commit 8eb3567, the pgai repository was vulnerable to an attack allowing the...
Medium - CVE-2025-6201 - The Pixel Manager for WooCommerce – Track...
The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Medium - CVE-2025-4367 - The Download Manager plugin for WordPress is...
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpdm_user_dashboard shortcode in all versions up to, and including, 3.3.18 due to...