NA - CVE-2025-6001 - A Cross-Site Request Forgery (CSRF)...
A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. An attacker is able to craft a special CSRF...
NA - CVE-2025-6002 - An unrestricted file upload vulnerability...
An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated attackers can upload files with arbitrary extensions, including executable or...
NA - CVE-2025-0913 - os.OpenFile(path, os.O_CREATE|O_EXCL) behaved...
os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never...
Medium - CVE-2025-0917 - IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2,...
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to...
Medium - CVE-2025-0923 - IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2,...
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 stores source code on the web server that could aid in further attacks against the system.
High - CVE-2025-25032 - IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2,...
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an authenticated user to cause a denial of service by sending a specially crafted...
NA - CVE-2025-40912 - CryptX for Perl before version 0.065 contains a...
CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds the tomcrypt library. The versions of that library in CryptX before 0.065 may...
NA - CVE-2025-49150 - Cursor is a code editor built for programming...
Cursor is a code editor built for programming with AI. Prior to 0.51.0, by default, the setting json.schemaDownload.enable was set to True. This means that by writing a JSON file, an attacker can...
NA - CVE-2025-30085 - Remote code execution vulnerability in...
Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative access to the...