A vulnerability was found in IBM Hardware Management Console DS8A00/DS8900F. It has been declared as problematic. This vulnerability affects unknown code of the component HCM. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-45094. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as very critical was found in IBM Tivoli Monitoring up to 6.3.0.7 SP15. This vulnerability affects unknown code. The manipulation of the argument index leads to improper validation of specified index, position, or offset in input.
This vulnerability was named CVE-2025-3357. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability has been found in haxtheweb HAXCMSSite up to 10.0.6 and classified as critical. This vulnerability affects unknown code. The manipulation of the argument location leads to path traversal.
This vulnerability was named CVE-2025-49138. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Listmonk up to 4.1.0. It has been classified as critical. Affected is the function QuerySubscribers. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2025-46011. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability has been found in AMD Platform Loader and Manager and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SSS. The manipulation leads to incorrect calculation.
This vulnerability is known as CVE-2025-0036. It is possible to launch the attack on the local host. There is no exploit available.
A vulnerability classified as critical was found in SAP MDM Server 710.750. This vulnerability affects the function ReadString of the component Packets Handler. The manipulation leads to free of memory not on the heap.
This vulnerability was named CVE-2025-42994. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as problematic, was found in SAP Business One Integration Framework B1_ON_HANA 10.0/SAP-M-BO 10.0. Affected is an unknown function of the component Security Setting Handler. The manipulation leads to origin validation error.
This vulnerability is traded as CVE-2025-42998. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in AMD Platform Loader and Manager. It has been declared as problematic. This vulnerability affects unknown code of the component PLM Runtime Service. The manipulation leads to improper input validation.
This vulnerability was named CVE-2025-0037. Local access is required to approach this attack. There is no exploit available.
A vulnerability was found in SAP NetWeaver Application Server for ABAP 7.89/7.93/9.14/9.15 and classified as problematic. Affected by this issue is some unknown functionality of the component RFC Inbound Handler. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2025-42989. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/roles/check.php of the component User Selector. The manipulation of the argument ID Number leads to cross site scripting.
This vulnerability is handled as CVE-2024-3931. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in qpdf 11.9.0. It has been rated as problematic. This issue affects the function std::__shared_count in the library /bits/shared_ptr_base.h. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2024-24246. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability classified as problematic has been found in GNU libmicrohttpd up to 0.9.75. Affected is the function MHD_create_post_processor of the component Multipart Form Parser. The manipulation of the argument boundary leads to out-of-bounds read.
This vulnerability is traded as CVE-2023-27371. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.