RSS Feeds > Computer & Technik > Internet > Marketing > scip AG [Security - Consulting - Information - Process] | RSS Verzeichnis

scip AG [Security - Consulting - Information - Process]


Anzeigen einer beliebigen Anzahl von Sicherheitsl?cken aus der scip AG Datenbank.

Betreiber-URL: https://www.scip.ch
RSS-Feed-URL: https://www.scip.ch/alertRSS.xml
Die neuesten Einträge aus dem RSS-Feed von scip AG [Security - Consulting - Information - Process]:
CVE-2025-14940 | code-projects Scholars Tracking System 1.0 /admin/delete_user.php ID sql injection
18.12.2025 23:09
A vulnerability was found in code-projects Scholars Tracking System 1.0. It has been rated as critical. The affected element is an unknown function of the file /admin/delete_user.php. This manipulatio...
CVE-2025-14939 | code-projects Online Appointment Booking System 1.0 /admin/deletemanager.php managername sql injection
18.12.2025 23:00
A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been declared as critical. Impacted is an unknown function of the file /admin/deletemanager.php. The manipulati...
CVE-2025-11747 | Colibri Page Builder Plugin up to 1.0.345 on WordPress colibri_blog_posts cross site scripting
18.12.2025 22:56
A vulnerability was found in Colibri Page Builder Plugin up to 1.0.345 on WordPress. It has been classified as problematic. This issue affects the function colibri_blog_posts. The manipulation leads t...
CVE-2025-13999 | HTML5 Audio Player Plugin up to 2.4.0/2.5.1 on WordPress getIcyMetadata server-side request forgery
18.12.2025 22:56
A vulnerability was found in HTML5 Audio Player Plugin up to 2.4.0/2.5.1 on WordPress and classified as critical. This vulnerability affects the function getIcyMetadata. Executing manipulation can lea...
CVE-2025-14449 | BA Book Everything Plugin up to 1.8.14 on WordPress Shortcode babe-search-form cross site scripting
18.12.2025 22:56
A vulnerability has been found in BA Book Everything Plugin up to 1.8.14 on WordPress and classified as problematic. This affects the function babe-search-form of the component Shortcode Handler. Perf...
CVE-2025-14151 | SlimStat Analytics Plugin up to 5.3.2 on WordPress outbound_resource cross site scripting
18.12.2025 22:56
A vulnerability, which was classified as problematic, was found in SlimStat Analytics Plugin up to 5.3.2 on WordPress. Affected by this issue is some unknown functionality. Such manipulation of the ar...
CVE-2025-14455 | Image Photo Gallery Final Tiles Grid Plugin up to 3.6.7 on WordPress authorization
18.12.2025 22:56
A vulnerability, which was classified as critical, has been found in Image Photo Gallery Final Tiles Grid Plugin up to 3.6.7 on WordPress. Affected by this vulnerability is an unknown functionality. T...
CVE-2025-12361 | myCred Plugin up to 2.9.7.1 on WordPress get_bank_accounts authorization
18.12.2025 22:55
A vulnerability classified as problematic was found in myCred Plugin up to 2.9.7.1 on WordPress. Affected is the function get_bank_accounts. The manipulation results in missing authorization. This vu...
CVE-2025-13754 | Appointment Booking Calendar Plugin up to 1.6.9.16 on WordPress embed-inner-admin authorization
18.12.2025 22:55
A vulnerability classified as problematic has been found in Appointment Booking Calendar Plugin up to 1.6.9.16 on WordPress. This impacts an unknown function of the file /wp-json/ssa/v1/embed-inner-ad...
CVE-2025-66524 | Apache NiFi up to 2.6.0 GetAsanaObject Processor deserialization
18.12.2025 22:53
A vulnerability described as critical has been identified in Apache NiFi up to 2.6.0. This affects an unknown function of the component GetAsanaObject Processor. Executing manipulation can lead to des...
CVE-2025-34452 | Streama up to 1.10.5 Subtitle path traversal (b7c8767)
18.12.2025 22:52
A vulnerability marked as critical has been reported in Streama up to 1.10.5. The impacted element is an unknown function of the component Subtitle Handler. Performing manipulation results in path tra...
CVE-2025-68388 | Elastic Packetbeat up to 7.17.29/8.19.8/9.1.8/9.2.2 allocation of resources
18.12.2025 22:52
A vulnerability labeled as critical has been found in Elastic Packetbeat up to 7.17.29/8.19.8/9.1.8/9.2.2. The affected element is an unknown function. Such manipulation leads to allocation of resourc...
CVE-2023-53936 | tuzitio Cameleon CMS 2.7.4 SVG cross site scripting (Exploit 51446 / EDB-51446)
18.12.2025 22:51
A vulnerability identified as problematic has been detected in tuzitio Cameleon CMS 2.7.4. Impacted is an unknown function of the component SVG Handler. This manipulation causes cross site scripting. ...
CVE-2023-53737 | Kentico Xperience up to 13.0.101 Administration Interface cross site scripting
18.12.2025 22:51
A vulnerability categorized as problematic has been discovered in Kentico Xperience up to 13.0.101. This issue affects some unknown processing of the component Administration Interface. The manipulati...
CVE-2022-50685 | Kentico Xperience up to 13.0.56 XML File Parser cross site scripting
18.12.2025 22:51
A vulnerability was found in Kentico Xperience up to 13.0.56. It has been rated as problematic. This vulnerability affects unknown code of the component XML File Parser. The manipulation leads to cros...
CVE-2024-58319 | Kentico Xperience up to 13.0.160 Pages Dashboard cross site scripting
18.12.2025 22:50
A vulnerability was found in Kentico Xperience up to 13.0.160. It has been declared as problematic. This affects an unknown part of the component Pages Dashboard. Executing manipulation can lead to cr...
CVE-2024-58318 | Kentico Xperience up to 13.0.162 cross site scripting
18.12.2025 22:50
A vulnerability was found in Kentico Xperience up to 13.0.162. It has been classified as problematic. Affected by this issue is some unknown functionality. Performing manipulation results in cross sit...
CVE-2023-53738 | Kentico Xperience up to 13.0.109 cross site scripting
18.12.2025 22:50
A vulnerability was found in Kentico Xperience up to 13.0.109 and classified as problematic. Affected by this vulnerability is an unknown functionality. Such manipulation leads to cross site scripting...
CVE-2024-58323 | Kentico Xperience up to 13.0.158 cross site scripting
18.12.2025 22:50
A vulnerability has been found in Kentico Xperience up to 13.0.158 and classified as problematic. Affected is an unknown function. This manipulation causes cross site scripting. This vulnerability is...
CVE-2024-58322 | Kentico Xperience up to 13.0.158 Shipping Options Configuration cross site scripting
18.12.2025 22:50
A vulnerability, which was classified as problematic, was found in Kentico Xperience up to 13.0.158. This impacts an unknown function of the component Shipping Options Configuration Handler. The manip...
CVE-2024-58321 | Kentico Xperience up to 13.0.159 Rule Configuration cross site scripting
18.12.2025 22:50
A vulnerability, which was classified as problematic, has been found in Kentico Xperience up to 13.0.159. This affects an unknown function of the component Rule Configuration Handler. The manipulation...
CVE-2023-53736 | Kentico Xperience up to 13.0.120 Administration Interface cross site scripting
18.12.2025 22:50
A vulnerability classified as problematic was found in Kentico Xperience up to 13.0.120. The impacted element is an unknown function of the component Administration Interface. Executing manipulation c...
CVE-2023-53939 | TinyWebGallery 2.5 cross site scripting (Exploit 51442 / EDB-51442)
18.12.2025 22:49
A vulnerability classified as problematic has been found in TinyWebGallery 2.5. The affected element is an unknown function. Performing manipulation results in cross site scripting. This vulnerabilit...
CVE-2022-50683 | Kentico Xperience up to 13.0.74 Setting cross site scripting
18.12.2025 22:49
A vulnerability described as problematic has been identified in Kentico Xperience up to 13.0.74. Impacted is an unknown function of the component Setting Handler. Such manipulation leads to cross site...
CVE-2022-50681 | Kentico Xperience up to 13.0.88 cross site scripting
18.12.2025 22:49
A vulnerability marked as problematic has been reported in Kentico Xperience up to 13.0.88. This issue affects some unknown processing. This manipulation causes cross site scripting. This vulnerabili...
CVE-2022-50680 | Kentico Xperience up to 13.0.92 cross site scripting
18.12.2025 22:48
A vulnerability labeled as problematic has been found in Kentico Xperience up to 13.0.92. This vulnerability affects unknown code. The manipulation results in cross site scripting. This vulnerability...
CVE-2025-59529 | Avahi up to 0.9-rc2 server_work resource consumption (GHSA-73wf-3xmj-x82q)
18.12.2025 22:48
A vulnerability identified as problematic has been detected in Avahi up to 0.9-rc2. This affects the function server_work. The manipulation leads to resource consumption. This vulnerability is listed...
CVE-2023-53938 | iwind RockMongo 1.1.7 cross site scripting (Exploit 51437 / EDB-51437)
18.12.2025 22:45
A vulnerability categorized as problematic has been discovered in iwind RockMongo 1.1.7. Affected by this issue is some unknown functionality. Executing manipulation can lead to cross site scripting. ...
CVE-2025-53710 | Palantir com.palantir.compute:compute-service Foundry Container Service improper isolation or compartmentalization
18.12.2025 22:45
A vulnerability was found in Palantir com.palantir.compute:compute-service. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Foundry Container...
CVE-2024-58317 | Kentico Xperience up to 13.0.164 web.config missing secure attribute
18.12.2025 22:45
A vulnerability was found in Kentico Xperience up to 13.0.164. It has been declared as problematic. Affected is an unknown function of the file web.config. Such manipulation leads to sensitive cookie ...
CVE-2022-50684 | Kentico Xperience up to 13.0.71 Form Submission cross site scripting
18.12.2025 22:44
A vulnerability was found in Kentico Xperience up to 13.0.71. It has been classified as problematic. This impacts an unknown function of the component Form Submission Handler. This manipulation causes...
CVE-2023-53943 | glpi-project glpi 9.5.7 Password Reset Endpoint information exposure (Exploit 51418 / EDB-51418)
18.12.2025 22:44
A vulnerability was found in glpi-project glpi 9.5.7 and classified as problematic. This affects an unknown function of the component Password Reset Endpoint. The manipulation results in information e...
CVE-2025-62002 | BullWall Ransomware Containment 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4 security check
18.12.2025 22:44
A vulnerability has been found in BullWall Ransomware Containment 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4 and classified as problematic. The impacted element is an unknown function. The manipulation leads to ...
CVE-2022-50682 | Kentico Xperience up to 13.0.79 crlf injection
18.12.2025 22:44
A vulnerability, which was classified as problematic, was found in Kentico Xperience up to 13.0.79. The affected element is an unknown function. Executing manipulation can lead to crlf injection. Thi...
CVE-2021-47712 | Kentico Xperience up to 12.0.102 risky encryption
18.12.2025 22:44
A vulnerability, which was classified as problematic, has been found in Kentico Xperience up to 12.0.102. Impacted is an unknown function. Performing manipulation results in risky cryptographic algori...
CVE-2021-47711 | Kentico Xperience up to 13.0.52 sql injection
18.12.2025 22:44
A vulnerability classified as critical was found in Kentico Xperience up to 13.0.52. This issue affects some unknown processing. Such manipulation leads to sql injection. This vulnerability is traded...
CVE-2022-50686 | Kentico Xperience up to 12.0 information exposure
18.12.2025 22:44
A vulnerability classified as problematic has been found in Kentico Xperience up to 12.0. This vulnerability affects unknown code. This manipulation causes information exposure through error message. ...
CVE-2024-58320 | Kentico Xperience up to 13.0.159 Administration Interface exposure of sensitive system information to an unauthorized control sphere
18.12.2025 22:44
A vulnerability described as problematic has been identified in Kentico Xperience up to 13.0.159. This affects an unknown part of the component Administration Interface. The manipulation results in ex...
CVE-2025-34451 | rofl0r proxychains-ng up to 4.17 src/libproxychains.c proxy_from_string username/password stack-based overflow (SAID-2025-008 / cc005b7)
18.12.2025 22:42
A vulnerability marked as critical has been reported in rofl0r proxychains-ng up to 4.17. Affected by this issue is the function proxy_from_string in the library src/libproxychains.c. The manipulation...
CVE-2023-53934 | Kentico Xperience up to 12.0.98 GetResource neutralization of directives
18.12.2025 22:42
A vulnerability labeled as critical has been found in Kentico Xperience up to 12.0.98. Affected by this vulnerability is an unknown functionality of the component GetResource Handler. Executing manipu...
CVE-2025-63947 | phpMsAdmin 2.2 database_mode.php dbname cross site scripting
18.12.2025 22:41
A vulnerability identified as problematic has been detected in phpMsAdmin 2.2. Affected is an unknown function of the file database_mode.php. Performing manipulation of the argument dbname results in ...
CVE-2025-34450 | merbanan rtl_433 up to 25.02 src/rfraw.c parse_rfraw stack-based overflow (SAID-2025-004 / 25e47f8)
18.12.2025 22:41
A vulnerability categorized as critical has been discovered in merbanan rtl_433 up to 25.02. This impacts the function parse_rfraw of the file src/rfraw.c. Such manipulation leads to stack-based buffe...
CVE-2025-34449 | Genymobile scrcpy up to 3.3.3 sc_device_msg_deserialize/process_msgs memory corruption (SAID-2025-003 / 3e40b24)
18.12.2025 22:39
A vulnerability was found in Genymobile scrcpy up to 3.3.3. It has been rated as critical. This affects the function sc_device_msg_deserialize/process_msgs. This manipulation causes memory corruption....
CVE-2025-13911 | Inductive Automation Ignition 8.1.x/8.3.x on Windows unnecessary privileges
18.12.2025 22:38
A vulnerability was found in Inductive Automation Ignition 8.1.x/8.3.x on Windows. It has been declared as critical. The impacted element is an unknown function. The manipulation results in execution ...
CVE-2025-63949 | yohanawi Hotel Management System 87e004a pages/room.php Error cross site scripting
18.12.2025 22:38
A vulnerability was found in yohanawi Hotel Management System 87e004a. It has been classified as problematic. The affected element is an unknown function of the file pages/room.php. The manipulation o...
CVE-2023-53941 | EasyPHP Webserver 14.1 Setting /index.php?zone=settings app_service_control os command injection (Exploit 51430 / EDB-51430)
18.12.2025 22:38
A vulnerability was found in EasyPHP Webserver 14.1 and classified as critical. Impacted is an unknown function of the file /index.php?zone=settings of the component Setting Handler. Executing manipul...
CVE-2023-53935 | Codester WBiz Desk 1.2 Ticket Endpoint ticket.php tk sql injection (Exploit 51451 / EDB-51451)
18.12.2025 22:37
A vulnerability has been found in Codester WBiz Desk 1.2 and classified as critical. This issue affects some unknown processing of the file ticket.php of the component Ticket Endpoint. Performing mani...
CVE-2023-53942 | leefish File Thingie 2.5.7 command unrestricted upload (Exploit 51436 / EDB-51436)
18.12.2025 22:37
A vulnerability, which was classified as critical, was found in leefish File Thingie 2.5.7. This vulnerability affects unknown code. Such manipulation of the argument command leads to unrestricted upl...
CVE-2025-63948 | phpMsAdmin 2.2 database_mode.php dbname sql injection
18.12.2025 22:37
A vulnerability, which was classified as critical, has been found in phpMsAdmin 2.2. This affects an unknown part of the file database_mode.php. This manipulation of the argument dbname causes sql inj...
CVE-2023-53944 | EasyPHP Webserver 14.1 path traversal (Exploit 51430 / EDB-51430)
18.12.2025 22:35
A vulnerability classified as critical was found in EasyPHP Webserver 14.1. Affected by this issue is some unknown functionality. The manipulation results in path traversal. This vulnerability is kno...
CVE-2025-63950 | to3k Twittodon Application up to 2023-02-28 download.php unserialize obj deserialization
18.12.2025 22:34
A vulnerability classified as problematic has been found in to3k Twittodon Application up to 2023-02-28. Affected by this vulnerability is the function unserialize of the file download.php. The manipu...
CVE-2025-63951 | MiczFlor RPi-Jukebox-RFID GET Parameter rss-mp3.php unserialize rss deserialization
18.12.2025 22:33
A vulnerability described as problematic has been identified in MiczFlor RPi-Jukebox-RFID. Affected is the function unserialize of the file rss-mp3.php of the component GET Parameter Handler. Executin...
CVE-2025-14850 | Advantech WebAccess/SCADA 9.2.1 path traversal
18.12.2025 22:31
A vulnerability marked as critical has been reported in Advantech WebAccess and SCADA 9.2.1. This impacts an unknown function. Performing manipulation results in path traversal. This vulnerability is...
CVE-2025-14848 | Advantech WebAccess/SCADA 9.2.1 absolute path traversal
18.12.2025 22:31
A vulnerability labeled as problematic has been found in Advantech WebAccess and SCADA 9.2.1. This affects an unknown function. Such manipulation leads to absolute path traversal. This vulnerability ...
CVE-2025-67653 | Advantech WebAccess/SCADA 9.2.1 path traversal
18.12.2025 22:30
A vulnerability identified as critical has been detected in Advantech WebAccess and SCADA 9.2.1. The impacted element is an unknown function. This manipulation causes path traversal. This vulnerabili...
CVE-2025-46268 | Advantech WebAccess/SCADA 9.2.1 sql injection
18.12.2025 22:30
A vulnerability categorized as critical has been discovered in Advantech WebAccess and SCADA 9.2.1. The affected element is an unknown function. The manipulation results in sql injection. This vulner...
CVE-2025-67163 | Simple Machines Forum 2.1.6 Forum Name cross site scripting (GHSA-p2xm-x9fp-5r7x)
18.12.2025 22:30
A vulnerability was found in Simple Machines Forum 2.1.6. It has been rated as problematic. Impacted is an unknown function. The manipulation of the argument Forum Name leads to cross site scripting. ...
CVE-2025-14849 | Advantech WebAccess/SCADA 9.2.1 unrestricted upload
18.12.2025 22:30
A vulnerability was found in Advantech WebAccess and SCADA 9.2.1. It has been declared as critical. This issue affects some unknown processing. Executing manipulation can lead to unrestricted upload. ...
CVE-2020-36891 | Kentico Xperience up to 12.0.49 Content-Type cross site scripting
18.12.2025 22:29
A vulnerability was found in Kentico Xperience up to 12.0.49. It has been classified as problematic. This vulnerability affects unknown code of the component Content-Type Handler. Performing manipulat...
CVE-2020-36889 | Kentico Xperience up to 12.0.90 Administration Interface cross site scripting
18.12.2025 22:29
A vulnerability was found in Kentico Xperience up to 12.0.90 and classified as problematic. This affects an unknown part of the component Administration Interface. Such manipulation leads to cross sit...
CVE-2025-59949 | FreshRSS up to 1.27.0 cross-site request forgery (GHSA-w7f5-8vf9-f966)
18.12.2025 22:29
A vulnerability has been found in FreshRSS up to 1.27.0 and classified as problematic. Affected by this issue is some unknown functionality. This manipulation causes cross-site request forgery. The i...
CVE-2025-65561 | Free5GC 4.1.0 Header LocalNode.Sess denial of service (Issue 730)
18.12.2025 22:29
A vulnerability, which was classified as problematic, was found in Free5GC 4.1.0. Affected by this vulnerability is the function LocalNode.Sess of the component Header Handler. The manipulation result...
CVE-2025-65562 | Free5GC 4.1.0 LocalNode.DeleteSess/LocalNode.Sess denial of service (Issue 731)
18.12.2025 22:29
A vulnerability, which was classified as problematic, has been found in Free5GC 4.1.0. Affected is the function LocalNode.DeleteSess/LocalNode.Sess. The manipulation leads to denial of service. This ...
CVE-2025-62001 | BullWall Ransomware Containment 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4 unprotected alternate channel
18.12.2025 22:28
A vulnerability classified as very critical was found in BullWall Ransomware Containment 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4. This impacts an unknown function. Executing manipulation can lead to unprotect...
CVE-2025-62000 | BullWall Ransomware Containment 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4 incomplete comparison with missing factors
18.12.2025 22:28
A vulnerability classified as problematic has been found in BullWall Ransomware Containment 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4. This affects an unknown function. Performing manipulation results in incomp...
CVE-2020-36890 | Kentico Xperience up to 12.0.60 authorization
18.12.2025 22:28
A vulnerability described as critical has been identified in Kentico Xperience up to 12.0.60. The impacted element is an unknown function. Such manipulation leads to missing authorization. This vulne...
CVE-2019-25229 | Kentico Xperience up to 12.0.29 unrestricted upload
18.12.2025 22:28
A vulnerability marked as critical has been reported in Kentico Xperience up to 12.0.29. The affected element is an unknown function. This manipulation causes unrestricted upload. This vulnerability ...
CVE-2023-53937 | Hubstaff 1.6.13/1.6.14 wow64log.dll uncontrolled search path (Exploit 51461 / EDB-51461)
18.12.2025 22:27
A vulnerability labeled as problematic has been found in Hubstaff 1.6.13/1.6.14. Impacted is an unknown function in the library wow64log.dll. The manipulation results in uncontrolled search path. Thi...
CVE-2025-64400 | Palantir com.palantir.controlpanel:control-panel prior 1.1401.0 API access control
18.12.2025 22:25
A vulnerability identified as critical has been detected in Palantir com.palantir.controlpanel:control-panel. This issue affects some unknown processing of the component API. The manipulation leads to...
CVE-2025-65566 | omec-project upf 2.1.3-dev PFCP Endpoint denial of service (Issue 958)
18.12.2025 22:24
A vulnerability categorized as problematic has been discovered in omec-project upf 2.1.3-dev. This vulnerability affects unknown code of the component PFCP Endpoint. Executing manipulation can lead to...
CVE-2025-65568 | omec-project upf 2.1.3-dev parseFAR out-of-bounds (ID 962)
18.12.2025 22:24
A vulnerability was found in omec-project upf 2.1.3-dev. It has been rated as problematic. This affects the function parseFAR. Performing manipulation results in out-of-bounds read. This vulnerabilit...
CVE-2025-65567 | omec-project upf 2.1.3-dev Flow-Description Parser denial of service (Issue 959)
18.12.2025 22:24
A vulnerability was found in omec-project upf 2.1.3-dev. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Flow-Description Parser. Such manipu...
CVE-2025-67745 | Aiven-Open myhoard up to 1.2.x /dev/null transmission of private resources into a new sphere ('resource leak') (GHSA-v42r-6hr9-4hcr)
18.12.2025 22:23
A vulnerability was found in Aiven-Open myhoard up to 1.2.x. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file /dev/null. This manipulation cau...
CVE-2025-65565 | omec-project upf 2.1.3-dev PFCP Session Establishment Request denial of service (Issue 957)
18.12.2025 22:23
A vulnerability was found in omec-project upf 2.1.3-dev and classified as problematic. Affected is an unknown function of the component PFCP Session Establishment Request Handler. The manipulation res...
CVE-2025-65563 | omec-project upf up to 2.1.3-dev PFCP Association Setup Request denial of service (Issue 955)
18.12.2025 22:17
A vulnerability has been found in omec-project upf up to 2.1.3-dev and classified as problematic. This impacts an unknown function of the component PFCP Association Setup Request Handler. The manipula...
CVE-2025-63387 | Dify 1.9.1 Endpoint system-features improper authentication
18.12.2025 22:17
A vulnerability, which was classified as critical, was found in Dify 1.9.1. This affects an unknown function of the file /console/api/system-features of the component Endpoint. Executing manipulation ...
CVE-2019-25230 | Kentico Xperience up to 12.0.0 exposure of sensitive system information to an unauthorized control sphere
18.12.2025 22:17
A vulnerability, which was classified as problematic, has been found in Kentico Xperience up to 12.0.0. The impacted element is an unknown function. Performing manipulation results in exposure of sens...
CVE-2025-62003 | BullWall Server Intrusion Protection 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4 toctou
18.12.2025 22:17
A vulnerability classified as problematic was found in BullWall Server Intrusion Protection 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4. The affected element is an unknown function. Such manipulation leads to tim...
CVE-2019-25228 | Kentico Xperience up to 12.0.47 HTTP Header Referer exposure of sensitive system information to an unauthorized control sphere
18.12.2025 22:16
A vulnerability classified as problematic has been found in Kentico Xperience up to 12.0.47. Impacted is an unknown function of the component HTTP Header Handler. This manipulation of the argument Ref...
CVE-2025-56157 | Dify up to 1.5.1 docker-compose.yaml default credentials
18.12.2025 22:14
A vulnerability described as problematic has been identified in Dify up to 1.5.1. This issue affects some unknown processing of the file docker-compose.yaml. The manipulation results in use of default...
CVE-2025-62004 | BullWall Server Intrusion Protection 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4 toctou
18.12.2025 22:13
A vulnerability marked as problematic has been reported in BullWall Server Intrusion Protection 4.6.0.0/4.6.0.6/4.6.0.7/4.6.1.4. This vulnerability affects unknown code. The manipulation leads to time...
CVE-2023-53940 | Alfonzm Codigo Markdown Editor 1.0.1 Markdown File child_process code injection (Exploit 51432 / EDB-51432)
18.12.2025 22:13
A vulnerability labeled as critical has been found in Alfonzm Codigo Markdown Editor 1.0.1. This affects the function child_process of the component Markdown File Handler. Executing manipulation can l...
CVE-2025-65559 | Open5GS 2.7.5-49-g lib/pfcp/context.c ogs_pfcp_object_teid_hash_set denial of service (Issue 4135)
18.12.2025 22:12
A vulnerability identified as problematic has been detected in Open5GS 2.7.5-49-g. Affected by this issue is the function ogs_pfcp_object_teid_hash_set in the library lib/pfcp/context.c. Performing ma...
CVE-2025-68161 | Apache Log4j up to 2.25.2 Socket Appender certificate validation
18.12.2025 22:12
A vulnerability categorized as critical has been discovered in Apache Log4j up to 2.25.2. Affected by this vulnerability is an unknown functionality of the component Socket Appender. Such manipulation...
CVE-2025-65564 | omec-project upf 2.1.3-dev PFCP Endpoint RecoveryTimeStamp denial of service (Issue 956)
18.12.2025 22:12
A vulnerability was found in omec-project upf 2.1.3-dev. It has been rated as problematic. Affected is the function RecoveryTimeStamp of the component PFCP Endpoint. This manipulation causes denial of...
CVE-2025-14910 | Edimax BR-6208AC 1.02 FTP Daemon Service handle_retr path traversal
18.12.2025 19:39
A vulnerability was found in Edimax BR-6208AC 1.02. It has been declared as critical. This impacts the function handle_retr of the component FTP Daemon Service. The manipulation results in path traver...
CVE-2025-14739 | TP-Link WR940N/WR941ND up to 3.16.9/3.20.1 uninitialized pointer
18.12.2025 19:31
A vulnerability was found in TP-Link WR940N and WR941ND up to 3.16.9/3.20.1. It has been classified as critical. This affects an unknown function. The manipulation leads to uninitialized pointer. This...
CVE-2025-14909 | JeecgBoot up to 3.9.0 SysUserOnlineController.java SysUserOnlineController user session (Issue 9195)
18.12.2025 19:30
A vulnerability was found in JeecgBoot up to 3.9.0 and classified as problematic. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-b...
CVE-2025-14908 | JeecgBoot up to 3.9.0 Multi-Tenant Management SysTenantController.java ID improper authentication (Issue 9196)
18.12.2025 19:30
A vulnerability has been found in JeecgBoot up to 3.9.0 and classified as critical. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/jav...
CVE-2025-64235 | AmentoTech Tuturn Plugin up to 3.5 on WordPress path traversal
18.12.2025 19:23
A vulnerability, which was classified as critical, was found in AmentoTech Tuturn Plugin up to 3.5 on WordPress. Impacted is an unknown function. Such manipulation leads to path traversal. This vulne...
CVE-2025-14738 | TP-Link WA850RE up to V2_160527/V3_160922 httpd improper authentication
18.12.2025 19:22
A vulnerability, which was classified as critical, has been found in TP-Link WA850RE up to V2_160527/V3_160922. This issue affects some unknown processing of the component httpd. This manipulation cau...
CVE-2025-63002 | wpforchurch Sermon Manager Plugin up to 2.30.0 on WordPress authorization
18.12.2025 19:22
A vulnerability classified as problematic was found in wpforchurch Sermon Manager Plugin up to 2.30.0 on WordPress. This vulnerability affects unknown code. The manipulation results in missing authori...
CVE-2025-14737 | TP-Link WA850RE up to V2_160527/V3_160922 httpd os command injection
18.12.2025 19:22
A vulnerability classified as critical has been found in TP-Link WA850RE up to V2_160527/V3_160922. This affects an unknown part of the component httpd. The manipulation leads to os command injection....
CVE-2025-63043 | PickPlugins Post Grid and Gutenberg Blocks Plugin up to 2.3.19 on WordPress authorization
18.12.2025 19:21
A vulnerability described as problematic has been identified in PickPlugins Post Grid and Gutenberg Blocks Plugin up to 2.3.19 on WordPress. Affected by this issue is some unknown functionality. Execu...
CVE-2025-62998 | WP Messiah WP AI CoPilot Plugin up to 1.2.7 on WordPress insertion of sensitive information into sent data
18.12.2025 19:21
A vulnerability marked as problematic has been reported in WP Messiah WP AI CoPilot Plugin up to 1.2.7 on WordPress. Affected by this vulnerability is an unknown functionality. Performing manipulation...
CVE-2025-14900 | CodeAstro Real Estate Management System 1.0 Administrator Endpoint /admin/userdelete.php ID sql injection
18.12.2025 17:36
A vulnerability labeled as critical has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /admin/userdelete.php of the component Administrator Endp...
CVE-2025-14899 | CodeAstro Real Estate Management System 1.0 Administrator Endpoint /admin/stateadd.php sql injection
18.12.2025 17:36
A vulnerability identified as critical has been detected in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /admin/stateadd.php of the component Administrator...
CVE-2025-14898 | CodeAstro Real Estate Management System 1.0 Administrator Endpoint userbuilderdelete.php sql injection
18.12.2025 17:36
A vulnerability categorized as critical has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component A...
CVE-2025-14897 | CodeAstro Real Estate Management System 1.0 Administrator Endpoint useragentdelete.php sql injection
18.12.2025 17:36
A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as critical. The impacted element is an unknown function of the file /admin/useragentdelete.php of the compo...
CVE-2025-14896 | yuzutech kroki convert spec file access (EUVD-2025-204295)
18.12.2025 17:33
A vulnerability was found in yuzutech kroki. It has been declared as problematic. The affected element is the function convert. Executing manipulation of the argument spec can lead to files or directo...
RSS Feed eintragen

Machen Sie Ihren RSS-Feed bekannt und erhöhen Sie die Sichtbarkeit Ihrer Website!

RSS-Feed eintragen
RSS-Reader
RSS-Reader finden Sie unter unsere Übersicht: RSS-Reader
Die neuesten Feeds
Die Top-Feeds
meist gelesenen Feeds