NA - CVE-2025-27140 - WeGIA is a Web manager for charitable...
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This...
NA - CVE-2025-27141 - Metabase Enterprise Edition is the enterprise...
Metabase Enterprise Edition is the enterprise version of Metabase business intelligence and data analytics software. Starting in version 1.47.0 and prior to versions 1.50.36, 1.51.14, 1.52.11, and...
NA - CVE-2024-53542 - Incorrect access control in the component...
Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the...
NA - CVE-2024-53543 - NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time...
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the addProject method in the smarttimeplus/MySQLConnection endpoint.
NA - CVE-2024-53544 - NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time...
NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability via the getCookieNames method in the smarttimeplus/MySQLConnection endpoint.
NA - CVE-2024-56525 - In Public Knowledge Project (PKP) OJS, OMP, and...
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context,...
NA - CVE-2025-22974 - SQL Injection vulnerability in SeaCMS v.13.2...
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
NA - CVE-2025-27143 - Better Auth is an authentication and...
Better Auth is an authentication and authorization library for TypeScript. Prior to version 1.1.21, the application is vulnerable to an open redirect due to improper validation of the callbackURL...
NA - CVE-2025-27144 - Go JOSE provides an implementation of the...
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web...