High - CVE-2025-4129 - Authorization Bypass Through User-Controlled...
Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Identifiers.This issue affects PAVO Pay: before 13.05.2025.
High - CVE-2025-4130 - Use of Hard-coded Credentials vulnerability in...
Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.This issue affects PAVO Pay: before 13.05.2025.
NA - CVE-2025-6235 - In ExtremeControl before 25.5.12, a cross-site...
In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied...
NA - CVE-2025-6704 - An arbitrary file writing vulnerability in the...
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific...
NA - CVE-2025-7382 - A command injection vulnerability in WebAdmin...
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-auth code execution on High Availability (HA)...
NA - CVE-2025-7624 - An SQL injection vulnerability in the legacy...
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active...
Low - CVE-2025-7926 - A vulnerability, which was classified as...
A vulnerability, which was classified as problematic, was found in PHPGurukul Online Banquet Booking System 1.0. This affects an unknown part of the file /admin/booking-search.php. The manipulation...
NA - CVE-2025-43976 - The com.enflick.android.tn2ndLine application...
The com.enflick.android.tn2ndLine application through 24.17.1.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a...
NA - CVE-2025-43977 - The com.skt.prod.dialer application through...
The com.skt.prod.dialer application through 12.5.0 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via...
NA - CVE-2025-46116 - An issue was discovered in CommScope Ruckus...
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the...