The largest supply-chain compromise in the history of the NPM ecosystem has impacted roughly 10% of all cloud environments, but attackers made little profit off it. [...]
A vulnerability categorized as problematic has been discovered in Cisco Evolved Programmable Network Manager and Prime Infrastructure. This impacts an unknown function of the component Web-based Management Interface. Such manipulation leads to file inclusion.
This vulnerability is documented as CVE-2025-20269. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability marked as critical has been reported in michaelliao itranswarp up to 2.19. This issue affects the function doFilter. This manipulation causes improper access controls.
This vulnerability appears as CVE-2025-28041. The attacker needs to be present on the local network. There is no available exploit.
A vulnerability has been found in O2OA up to 10.0-410 and classified as problematic. This impacts an unknown function of the file /x_portal_assemble_designer/jaxrs/page of the component Personal Profile Page. Performing manipulation results in cross site scripting.
This vulnerability is identified as CVE-2025-9680. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability has been found in GalleryVault Gallery Vault App up to 4.5.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.thinkyeah.galleryvault. The manipulation leads to improper export of android application components.
This vulnerability is referenced as CVE-2025-9695. The attack can only be performed from a local environment. Furthermore, an exploit is available.
A vulnerability was found in O2OA up to 10.0-410 and classified as problematic. Affected is an unknown function of the file /x_program_center/jaxrs/agent of the component Personal Profile Page. Executing manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2025-9681. The attack can be launched remotely. Moreover, an exploit is present.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability was found in O2OA up to 10.0-410. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the file /x_cms_assemble_control/jaxrs/design/appdict of the component Personal Profile Page. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2025-9682. The attack may be initiated remotely. In addition, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability was found in O2OA up to 10.0-410. It has been declared as problematic. Affected by this issue is some unknown functionality of the file /x_cms_assemble_control/jaxrs/form of the component Personal Profile Page. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-9683. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. Executing manipulation of the argument Username can lead to sql injection.
The identification of this vulnerability is CVE-2025-9694. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Dell iDRAC Service Module up to 6.0.3.0. It has been declared as problematic. Affected by this issue is some unknown functionality. The manipulation results in incorrect permission assignment.
This vulnerability is known as CVE-2025-38742. Attacking locally is a requirement. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Commvault CommCell up to 11.32.101/11.36.59 and classified as problematic. The impacted element is an unknown function of the component Administrator Login Handler. This manipulation causes storing passwords in a recoverable format.
This vulnerability is handled as CVE-2025-57789. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in Commvault CommCell up to 11.32.101/11.36.59 and classified as very critical. This affects an unknown function. Such manipulation leads to absolute path traversal.
This vulnerability is uniquely identified as CVE-2025-57790. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability was found in Commvault CommCell up to 11.32.101/11.36.59. It has been classified as critical. This impacts an unknown function. Performing manipulation results in argument injection.
This vulnerability was named CVE-2025-57791. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.