A vulnerability, which was classified as problematic, has been found in Elseplus File Recovery App 4.4.21 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml. This manipulation causes improper export of android application components.
The identification of this vulnerability is CVE-2025-9098. The attack can only be executed locally. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in Acrel Environmental Monitoring Cloud Platform up to 20250804. Affected by this issue is some unknown functionality of the file /NewsManage/UploadNewsImg. Such manipulation of the argument File leads to unrestricted upload.
This vulnerability is referenced as CVE-2025-9099. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Oracle MySQL Server up to 8.0.23. It has been declared as critical. Affected by this issue is some unknown functionality of the component Optimizer. The manipulation results in denial of service.
This vulnerability is reported as CVE-2021-2203. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability marked as critical has been reported in Linux Kernel. This impacts an unknown function of the component SCTP Stack. The manipulation leads to improper validation of integrity check value.
This vulnerability is listed as CVE-2021-3772. The attack may be initiated remotely. There is no available exploit.
Applying a patch is the recommended action to fix this issue.
A vulnerability classified as critical was found in Mozilla Firefox up to 124. Affected by this issue is some unknown functionality of the component Garbage Collection Handler. Executing manipulation can lead to use after free.
This vulnerability is tracked as CVE-2024-3853. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability labeled as problematic has been found in Linux Kernel up to 5.3.3. The impacted element is the function fib6_rule_lookup of the file net/ipv6/ip6_fib.c. The manipulation of the argument RT6_LOOKUP_F_DST_NOREF as part of Flag results in handling of exceptional conditions.
This vulnerability is identified as CVE-2019-20422. The attack is only possible with local access. There is not any exploit available.
The affected component should be upgraded.
A vulnerability marked as problematic has been reported in Linux Kernel up to 5.5. Impacted is the function go7007_snd_init of the file drivers/media/usb/go7007/snd-go7007.c. Performing manipulation results in missing release of resource.
This vulnerability is known as CVE-2019-20810. Attacking locally is a requirement. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability marked as problematic has been reported in Linux Kernel up to 5.10.36/5.11.20/5.12.3. Affected by this issue is the function zynqmp_qspi_exec_op of the component spi-zynqmp-gqspi. This manipulation causes use after free.
This vulnerability is handled as CVE-2021-47048. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 5.18.17/5.19.1 and classified as critical. This impacts the function readahead_folio of the component cifs. Performing manipulation results in memory leak.
This vulnerability was named CVE-2022-50107. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
A vulnerability classified as problematic has been found in ExpressGateway express-gateway up to 1.16.10. This impacts an unknown function in the library lib/rest/routes/apps.js of the component REST Endpoint. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-9096. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability marked as critical has been reported in ThingsBoard 4.1. The impacted element is an unknown function of the component Add Gateway Handler. Performing manipulation results in improper neutralization of special elements used in a template engine.
This vulnerability is known as CVE-2025-9094. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."