NA - CVE-2025-35940 - The ArchiverSpaApi ASP.NET application uses a...
The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated remote attacker can generate and use a verifiable JWT token to access protected ArchiverSpaApi URL...
High - CVE-2025-5978 - A vulnerability was found in Tenda FH1202...
A vulnerability was found in Tenda FH1202 1.2.0.14. It has been classified as critical. Affected is the function fromVirtualSer of the file /goform/VirtualSer. The manipulation of the argument page...
High - CVE-2025-5979 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in code-projects School Fees Payment System 1.0. This affects an unknown part of the file /branch.php. The manipulation of the argument ID...
High - CVE-2025-5980 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affects unknown code of the file /order.php. The manipulation of the argument...
Medium - VU#806555 - A Vulnerability in UEFI Applications allows for secure boot bypass via misused NVRAM variable
OverviewUEFI firmware applications DTBios and BiosFlashShell from DTResearch contain a vulnerability that allows Secure Boot to be bypassed using a specially crafted NVRAM variable. The...
NA - CVE-2025-22829 - The CloudStack Quota plugin has an improper...
The CloudStack Quota plugin has an improper privilege management logic in version 4.20.0.0. Anyone with authenticated user-account access in CloudStack 4.20.0.0 environments, where this plugin is...
NA - CVE-2025-26521 - When an Apache CloudStack user-account creates...
When an Apache CloudStack user-account creates a CKS-based Kubernetes cluster in a project, the API key and the secret key of the 'kubeadmin' user of the caller account are used to create...
High - CVE-2025-46837 - Adobe Experience Manager versions 6.5.22 and...
Adobe Experience Manager versions 6.5.22 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious...
Medium - CVE-2025-46838 - Adobe Experience Manager versions 6.5.22 and...
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts...
High - CVE-2025-46840 - Adobe Experience Manager versions 6.5.22 and...
Adobe Experience Manager versions 6.5.22 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low privileged attacker could leverage this...