NA - CVE-2025-49198 - The Media Server’s authorization tokens have a...
The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens.
NA - CVE-2025-49199 - The backup ZIPs are not signed by the...
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the...
NA - CVE-2025-49200 - The created backup files are unencrypted,...
The created backup files are unencrypted, making the application vulnerable for gathering sensitive information by downloading and decompressing the backup files.
NA - CVE-2024-7562 - A potential elevated privilege issue has been...
A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versions (InstallShield...
NA - CVE-2025-36573 - Dell Smart Dock Firmware, versions prior to...
Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local access could potentially exploit this...
NA - CVE-2025-46035 - Buffer Overflow vulnerability in Tenda AC6...
Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized schedStartTime and schedEndTime parameters in an unauthenticated...
NA - CVE-2025-49467 - A SQL injection vulnerability in JEvents...
A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events...