NA - CVE-2024-51144 - Cross Site Request Forgery (CSRF) vulnerability...
Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints...
NA - CVE-2025-27517 - Volt is an elegantly crafted functional API for...
Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lead to remote code execution within Volt components. This vulnerability is...
NA - CVE-2024-57174 - A misconfiguration in Alphion ASEE-1443...
A misconfiguration in Alphion ASEE-1443 Firmware v0.4.H.00.02.15 defines a previously unregistered domain name as the default DNS suffix. This allows attackers to register the unclaimed domain and...
NA - CVE-2025-25362 - A Server-Side Template Injection (SSTI)...
A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.
NA - CVE-2025-25634 - A vulnerability has been found in Tenda AC15...
A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based...
NA - CVE-2025-27516 - Jinja is an extensible templating engine. Prior...
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a...
NA - CVE-2025-27508 - Emissary is a P2P based data-driven workflow...
Emissary is a P2P based data-driven workflow engine. The ChecksumCalculator class within allows for hashing and checksum generation, but it includes or defaults to algorithms that are no longer...
NA - CVE-2025-27622 - Jenkins 2.499 and earlier, LTS 2.492.1 and...
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read...