NA - CVE-2025-27152 - axios is a promise based HTTP client for the...
axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ?baseURL is set, axios sends the...
NA - CVE-2025-27518 - Cognita is a RAG (Retrieval Augmented...
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. An insecure CORS configuration in the Cognita backend...
NA - CVE-2025-27519 - Cognita is a RAG (Retrieval Augmented...
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. A path traversal issue exists at...
NA - CVE-2025-27597 - Vue I18n is the internationalization plugin for...
Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An...
NA - CVE-2025-27603 - XWiki Confluence Migrator Pro helps admins to...
XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped...
Medium - CVE-2023-35894 - IBM Control Center 6.2.1 through 6.3.1 is...
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks...
Medium - CVE-2023-43052 - IBM Control Center 6.2.1 through 6.3.1 is...
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to an external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this...
NA - CVE-2024-13086 - An exposure of sensitive information...
An exposure of sensitive information vulnerability has been reported to affect product. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We...
NA - CVE-2024-38638 - An out-of-bounds write vulnerability has been...
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator...