A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2025-3018. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, has been found in TA-Lib up to 0.6.4. This issue affects the function setInputBuffer of the file src/tools/ta_regtest/ta_test_func/test_minmax.c of the component ta_regtest. The manipulation leads to out-of-bounds write.
The identification of this vulnerability is CVE-2025-3017. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption.
This vulnerability was named CVE-2025-3016. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-3015. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in PiExtract SOOP-CLM up to 5.3.0. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2025-3011. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in HPE Insight Cluster Management Utility 8.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to privilege escalation. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2024-13804. The attack can only be done within the local network. There is no exploit available.
A vulnerability was found in Appleple A-Blog CMS up to 3.1.36. It has been classified as critical. Affected is an unknown function of the component Request Handler. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2025-31103. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in FPT NightWolf Penetration Platform up to 2.1.4 and classified as critical. This issue affects some unknown processing of the component Customer Portal. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2025-3013. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.