A vulnerability was found in Qualitor 8.24. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument gridValoresPopHidden leads to code injection.
The identification of this vulnerability is CVE-2024-48359. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as critical has been found in Revenera InstallShield 2021 R2/2022 R2/2023 R2. This affects an unknown part of the component Standalone MSI Setup. The manipulation leads to creation of temporary file in directory with insecure permissions.
This vulnerability is uniquely identified as CVE-2024-7562. The attack needs to be approached locally. There is no exploit available.
A vulnerability was found in vantage6 up to 4.10.x. It has been declared as problematic. This vulnerability affects unknown code of the component Change Password Handler. The manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability was named CVE-2025-43863. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Ivanti Workspace Control up to 10.18.50.0. It has been classified as critical. Affected is an unknown function of the component Management Console. The manipulation leads to uncontrolled search path.
This vulnerability is traded as CVE-2024-44107. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in GWE Systems JEvents Component up to 3.6.87 on Joomla. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-49467. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Dell Smart Dock and classified as problematic. This issue affects some unknown processing. The manipulation leads to sensitive information in log files.
The identification of this vulnerability is CVE-2025-36573. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in uptrace pgdriver 1.2.1. It has been declared as critical. Affected by this vulnerability is the function appendArg of the file /pgdriver/format.go. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-44906. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in pg-promise up to 11.5.4. It has been rated as critical. Affected by this issue is some unknown functionality of the component Negative Number Handler. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2025-29744. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in vantage6 up to 4.10. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to insufficiently random values.
The identification of this vulnerability is CVE-2025-43866. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in rubentd gifplayer up to 0.3.6 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2025-31128. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in AmauriC tarteaucitron.js up to 1.20.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-31476. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Absolute Security Secure Access up to 13.53 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to denial of service.
This vulnerability is known as CVE-2025-49080. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Absolute Security Secure Access up to 13.54. Affected by this issue is some unknown functionality of the component Warehouse. The manipulation leads to permission issues.
This vulnerability is handled as CVE-2025-49081. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in MobSF Mobile-Security-Framework-MobSF up to 4.3.1 and classified as problematic. This vulnerability affects the function valid_host. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2025-31116. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in xwiki-platform up to 15.10.15/16.4.6/16.10.1. Affected by this issue is the function DBMS_XMLGEN/DBMS_XMLQUERY. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-56158. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.