NA - CVE-2024-53349 - Insecure permissions in kuadrant v0.11.3 allow...
Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escalation of privileges via the secretes component in the k8s cluster
NA - CVE-2025-29226 - In Linksys E5600 V1.1.0.26, the...
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["count"] parameter.
NA - CVE-2025-29227 - In Linksys E5600 V1.1.0.26, the...
In Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function via the pt["pkgsize"] parameter.
NA - CVE-2025-29230 - Linksys E5600 v1.1.0.26 was discovered to...
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can be triggered via the `pt["email"]` parameter.
NA - CVE-2025-30349 - Horde IMP through 6.2.27, as used with Horde...
Horde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted text/html e-mail message with an onerror attribute (that...
NA - CVE-2025-25035 - Improper Neutralization of Input During Web...
Improper Neutralization of Input During Web Page Generation Cross-site Scripting vulnerability in Jalios JPlatform 10 allows for Reflected XSS and Stored XSS.This issue affects JPlatform 10: before...
NA - CVE-2025-25036 - Improper Restriction of XML External Entity...
Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlatform 10 before 10.0.8 (SP8).