Critical - CVE-2024-12364 - Improper Neutralization of Special Elements...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yesil Software Guest Tracking Software allows SQL Injection.This issue affects ....
NA - CVE-2025-44557 - A state machine transition flaw in the...
A state machine transition flaw in the Bluetooth Low Energy (BLE) stack of Cypress PSoC4 v3.66 allows attackers to bypass the pairing process and authentication via a crafted pairing_failed packet.
NA - CVE-2025-44559 - An issue in the Bluetooth Low Energy (BLE)...
An issue in the Bluetooth Low Energy (BLE) stack of Realtek RTL8762E BLE SDK v1.4.0 allows attackers within Bluetooth range to cause a Denial of Service (DoS) via sending a specific sequence of...
NA - CVE-2025-53093 - TabberNeue is a MediaWiki extension that allows...
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Starting in version 3.0.0 and prior to version 3.1.1, any user can insert arbitrary HTMLinto the DOM by inserting a payload...
NA - CVE-2025-5310 - Dover Fueling Solutions ProGauge MagLink LX...
Dover Fueling Solutions ProGauge MagLink LX Consoles expose an undocumented and unauthenticated target communication framework (TCF) interface on a specific port. Files can be created, deleted, or...
NA - CVE-2025-6522 - Unauthenticated users on an adjacent network...
Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol available on Port 16668. This vulnerability...
High - CVE-2025-6772 - A vulnerability was found in eosphoros-ai...
A vulnerability was found in eosphoros-ai db-gpt up to 0.7.2. It has been classified as critical. Affected is the function import_flow of the file /api/v2/serve/awel/flow/import. The manipulation...
Medium - CVE-2025-6773 - A vulnerability was found in HKUDS LightRAG up...
A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function upload_to_input_dir of the file...
NA - CVE-2025-53094 - ESPAsyncWebServer is an asynchronous HTTP and...
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection...