High - CVE-2025-1687 - The Cardealer theme for WordPress is vulnerable...
The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile'...
NA - CVE-2025-25477 - A host header injection vulnerability in...
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.
NA - CVE-2025-25728 - Bosscomm IF740 Firmware versions:11001.7078 &...
Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 were discovered to send communications to the update API in plaintext, allowing attackers to access...
NA - CVE-2025-25729 - An information disclosure vulnerability in...
An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions: 6.25 & 6.00 allows attackers to obtain hardcoded cleartext credentials via...
Medium - CVE-2024-54173 - IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD...
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.
Medium - CVE-2024-56340 - IBM Cognos Analytics 11.2.0 through 11.2.4 FP5...
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the...
Medium - CVE-2025-0823 - IBM Cognos Analytics 11.2.0 through 11.2.4 FP5...
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request...
High - CVE-2025-0975 - IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD...
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.
Medium - CVE-2025-23225 - IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD...
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user to cause a denial of service due to the improper handling of invalid headers sent to the queue.