NA - CVE-2024-54820 - XOne Web Monitor v02.10.2024.530 framework...
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and...
NA - CVE-2025-27112 - Navidrome is an open source web-based music...
Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subsonic API endpoints, a flaw in the authentication...
NA - CVE-2025-27133 - WeGIA is a Web manager for charitable...
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA application prior to version 3.2.15 at the `adicionar_tipo_exame.php` endpoint. This...
NA - CVE-2025-27364 - In MITRE Caldera through 4.2.0 and 5.0.0 before...
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows...
NA - CVE-2025-26525 - Insufficient sanitizing in the TeX notation...
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).