Medium - CVE-2025-6135 - A vulnerability was found in Projectworlds Life...
A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /insertNominee.php. The...
NA - CVE-2025-32798 - Conda-build contains commands and tools to...
Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build recipe processing logic has been found to be vulnerable to arbitrary code execution due to...
Medium - CVE-2025-6136 - A vulnerability was found in Projectworlds Life...
A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insertPayment.php. The...
High - CVE-2025-6137 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP POST Request...
NA - CVE-2025-32799 - Conda-build contains commands and tools to...
Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due to improper...
NA - CVE-2025-32800 - Conda-build contains commands and tools to...
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An...
NA - CVE-2025-47951 - Weblate is a web based localization tool. Prior...
Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint...
NA - CVE-2025-49134 - Weblate is a web based localization tool. Prior...
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as...
High - CVE-2025-6138 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component HTTP...
Low - CVE-2025-6139 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The...