A vulnerability was found in Wireless Tsukamoto WTW-EAGLE App up to 4.4.0 on iOS/Android and classified as critical. Affected is an unknown function. Executing manipulation can lead to improper certificate validation.
This vulnerability is registered as CVE-2025-58781. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Contact Form 7 reCAPTCHA Plugin up to 1.2.0 on WordPress and classified as problematic. This impacts an unknown function. Performing manipulation of the argument REQUEST_URI results in cross site scripting.
This vulnerability is cataloged as CVE-2025-8280. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, was found in jQuery Colorbox Plugin up to 4.6.3 on WordPress. This affects an unknown function of the component Title Attribute Handler. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2025-3650. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as problematic, has been found in GitLab Community Edition and Enterprise Edition up to 18.1.5/18.2.5/18.3.1. The impacted element is an unknown function. This manipulation causes allocation of resources.
This vulnerability is tracked as CVE-2025-7337. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in GitLab Community Edition and Enterprise Edition up to 18.1.5/18.2.5/18.3.1. The affected element is an unknown function. The manipulation results in exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is identified as CVE-2025-6769. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in GitLab Community Edition and Enterprise Edition up to 18.1.5/18.2.5/18.3.1. Impacted is an unknown function. The manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2025-6454. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in GitLab Community Edition and Enterprise Edition up to 18.1.5/18.2.5/18.3.1. This issue affects some unknown processing of the component SAML Response Handler. Executing manipulation can lead to improper validation of specified quantity in input.
The identification of this vulnerability is CVE-2025-2256. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in GitLab Community Edition and Enterprise Edition up to 18.1.5/18.2.5/18.3.1. This vulnerability affects unknown code. Performing manipulation results in allocation of resources.
This vulnerability was named CVE-2025-1250. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
微软官方博客宣布,近 200 个国家的开发者只需要拥有个人的 Microsoft 帐户就可在其应用商店 Microsoft Store 免费发布应用。此前开发者在 Microsoft Store 发布应用需要支付一次性 19 美元的费用,苹果应用商店收费最贵——开发者需要每年支付 99 美元,而 Google 则是收取一次性 25 美元的注册费。微软称,Microsoft Store 每月有逾 2.5 亿活跃用户。微软允许开发者在其应用商店发布 Win32、UWP、PWA、.NET、MAUI 或 Electron 等不同类型的应用。开发者甚至允许使用自己的应用内交易系统,获得 100% 的非游戏应用收入。微软如此大方的一个原因是它的应用商店在 Windows 平台并不具有垄断性质,它需要吸引开发者使用其应用商店。
Currently trending CVE - Hype Score: 1 - Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a ...