A vulnerability was found in linlinjava litemall up to 1.8.0. It has been declared as critical. This affects an unknown function of the file AdminGoodscontroller.java. The manipulation of the argument goodsId/goodsSn/name results in sql injection.
This vulnerability is cataloged as CVE-2024-6452. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability identified as critical has been detected in linlinjava litemall up to 1.8.0. Affected by this issue is the function Upload of the file /wx/storage/upload. The manipulation of the argument File leads to unrestricted upload.
This vulnerability is referenced as CVE-2025-8764. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability has been found in linlinjava litemall up to 1.8.0 and classified as critical. This affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the component Endpoint. Performing manipulation of the argument File results in unrestricted upload.
This vulnerability is cataloged as CVE-2025-8965. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, has been found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Performing manipulation of the argument Title results in cross site scripting.
This vulnerability is reported as CVE-2025-9138. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor explains: "[T]he risks of indicated vulnerabilities seem to be minimal as all scenarios likely require admin permissions. Moreover, regardless our team fixes those vulnerabilities - the overall risk change to the user due to malicious admin actions will not be lower. An admin user - by definition - has full control over HTML and JS code that is delivered to users in regular synoptic panels. In other words - due to the design of the system it is not possible to limit the admin user to attack the users."
A vulnerability, which was classified as problematic, was found in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Executing manipulation can lead to information disclosure.
This vulnerability appears as CVE-2025-9139. The attack may be performed from remote. In addition, an exploit is available.
The vendor explains: "[T]he risks of indicated vulnerabilities seem to be minimal as all scenarios likely require admin permissions. Moreover, regardless our team fixes those vulnerabilities - the overall risk change to the user due to malicious admin actions will not be lower."
A vulnerability was found in Scada-LTS 2.7.8.1 and classified as problematic. This affects an unknown part of the file mailing_lists.shtm. The manipulation of the argument name/userList/address results in cross site scripting.
This vulnerability is known as CVE-2025-9143. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in Scada-LTS 2.7.8.1. It has been classified as problematic. This vulnerability affects unknown code of the file publisher_edit.shtm. This manipulation of the argument Name causes cross site scripting.
This vulnerability is handled as CVE-2025-9144. The attack can be initiated remotely. Additionally, an exploit exists.
A vulnerability classified as problematic has been found in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHelper.java of the component JSON Web Token Handler. This manipulation of the argument SECRET with the input X-Litemall-Token causes hard-coded credentials.
The identification of this vulnerability is CVE-2025-8974. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as problematic, was found in Scada-LTS up to 2.7.8.1. This impacts an unknown function of the file usersProfiles.shtm. The manipulation of the argument Username results in cross site scripting.
This vulnerability is known as CVE-2025-7729. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this issue and confirmed that it will be fixed in the upcoming release 2.8.0.
A vulnerability, which was classified as problematic, has been found in Scada-LTS up to 2.7.8.1. This affects an unknown function of the file users.shtm. The manipulation of the argument Username leads to cross site scripting.
This vulnerability is traded as CVE-2025-7728. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this issue and confirmed that it will be fixed in the upcoming release 2.8.0.
A vulnerability, which was classified as problematic, was found in Cisco IOS and IOS XE. Affected by this issue is some unknown functionality of the component Hot Standby Router Protocol Subystem. The manipulation results in improper initialization.
This vulnerability is known as CVE-2019-1761. Access to the local network is required for this attack. No exploit is available.
A vulnerability labeled as problematic has been found in Cisco IOS and IOS XE. This issue affects some unknown processing of the component IKEv2 Handler. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2021-1620. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization.
This vulnerability is handled as CVE-2025-10252. The attack can only be done within the local network. Additionally, an exploit exists.
It is advisable to implement restrictive firewalling.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as problematic, was found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifive.php of the component SVG File Handler. Such manipulation of the argument Filedata leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-10253. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability labeled as problematic has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file /data_source_edit.shtm of the component Virtual Data Source Property Handler. Such manipulation of the argument Name leads to cross site scripting.
This vulnerability is listed as CVE-2025-8743. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability marked as problematic has been reported in Portabilis i-Diario 1.5.0. Impacted is an unknown function of the file /diario-de-observacoes/ of the component Observações. Performing manipulation of the argument Descrição results in cross site scripting.
This vulnerability is cataloged as CVE-2025-8511. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability categorized as critical has been discovered in Node.js up to 20.19.1. Affected is an unknown function of the component HTTP Parser. Such manipulation leads to http request smuggling.
This vulnerability is documented as CVE-2025-23167. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in nodejs undici up to 5.28.4/6.21.0/7.2.2. This impacts the function Math.random of the component Multipart Request Handler. This manipulation causes insufficiently random values.
This vulnerability is handled as CVE-2025-22150. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.