NA - CVE-2024-30154 - HCL SX is vulnerable to cross-site request...
HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
Medium - CVE-2025-1877 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in D-Link DAP-1562 1.10. This affects the function pure_auth_check of the component HTTP POST Request Handler. The manipulation of the...
Low - CVE-2025-1878 - A vulnerability has been found in i-Drive i11...
A vulnerability has been found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This vulnerability affects unknown code of the component WiFi. The manipulation leads to use of...
NA - CVE-2025-1889 - picklescan before 0.0.22 only considers...
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle include a malicious...
NA - CVE-2025-25967 - Acora CMS version 10.1.1 is vulnerable to...
Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion...
NA - CVE-2025-27499 - WeGIA is an open source Web Manager for...
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the processa_edicao_socio.php...
NA - CVE-2025-27500 - OpenZiti is a free and open source project...
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) on the admin panel can be accessed without any form of authentication. This...
NA - CVE-2025-27501 - OpenZiti is a free and open source project...
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin panel can be accessed without any form of authentication. This endpoint...