NA - CVE-2024-54448 - The Automation Scripting functionality can be...
The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been...
NA - CVE-2024-54449 - The API used to interact with documents in the...
The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticated attacker to write a file with controlled contents to an arbitrary location...
NA - CVE-2025-29775 - xml-crypto is an XML digital signature and...
xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerability in versions prior to 6.0.1, 3.2.1, and 2.1.6 to bypass authentication...
NA - CVE-2025-29771 - HtmlSanitizer is a client-side HTML Sanitizer....
HtmlSanitizer is a client-side HTML Sanitizer. Versions prior to 2.0.3 have a cross-site scripting vulnerability when the sanitizer is used with a `contentEditable` element to set the elements...
NA - CVE-2025-29782 - WeGIA is Web manager for charitable...
WeGIA is Web manager for charitable institutions A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_tipo_docs_atendido.php` endpoint in versions of the WeGIA...
Medium - CVE-2025-2308 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_decompress_one_byte of the component Scale-Offset Filter. The manipulation...
Medium - CVE-2025-2309 - A vulnerability has been found in HDF5 1.14.6...
A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__bit_copy of the component Type Conversion Logic. The manipulation leads to...