A vulnerability labeled as critical has been found in Dromara RuoYi-Vue-Plus 5.4.0. Affected by this issue is some unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java of the component Mail Handler. The manipulation of the argument filePath results in path traversal.
This vulnerability is identified as CVE-2025-6925. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as problematic, was found in Dell PowerProtect Data Manager up to 19.19. Affected by this vulnerability is an unknown functionality. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2025-30480. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been declared as problematic. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.huuge.game.zjbox. Such manipulation leads to improper export of android application components.
This vulnerability is documented as CVE-2025-8707. The attack needs to be performed locally. Additionally, an exploit exists.
A vulnerability described as problematic has been identified in D-Link DI-8400 16.07.26A1. The impacted element is an unknown function of the file usb_paswd.asp of the component jhttpd. Such manipulation of the argument share_enable leads to null pointer dereference.
This vulnerability is listed as CVE-2025-8175. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability labeled as critical has been found in D-Link DIR-513 1.0. This affects the function formLanguageChange of the file /goform/formLanguageChange of the component HTTP POST Request Handler. Executing manipulation of the argument curTime can lead to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is tracked as CVE-2025-8159. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability has been found in Artica Pandora FMS up to 7.0NG and classified as critical. Affected by this issue is some unknown functionality of the file net_tools.php. This manipulation of the argument select_ips causes os command injection.
This vulnerability is handled as CVE-2025-34088. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in Bolt CMS up to 3.7.0. It has been classified as critical. This vulnerability affects unknown code of the file /async/browse/cache/.sessions. Performing manipulation of the argument displayname results in code injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-34086. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in NSClient++ 0.5.2.35. It has been declared as critical. Affected by this issue is some unknown functionality of the file /settings/query.json of the component Web Interface/ExternalScripts Module. Executing manipulation can lead to code injection.
This vulnerability is handled as CVE-2025-34079. The attack can be executed remotely. There is not any exploit available.
A vulnerability labeled as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. Affected is the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend. Such manipulation of the argument flag leads to path traversal.
This vulnerability is traded as CVE-2025-6853. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability labeled as critical has been found in Artica Pandora FMS 774/775/776/777/778. This vulnerability affects unknown code. Executing manipulation of the argument Netflow Directory can lead to command injection.
This vulnerability is handled as CVE-2025-5306. The attack can be executed remotely. There is not any exploit available.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.0.2. Impacted is the function dump_stack. The manipulation results in allocation of resources.
This vulnerability is cataloged as CVE-2022-50271. The attack must originate from the local network. There is no exploit available.
The affected component should be upgraded.
A vulnerability classified as critical has been found in Ilevia EVE X1 Server up to 4.7.18.0.eden. The affected element is an unknown function of the file /ajax/php/login.php of the component POST Parameter Handler. Performing manipulation of the argument passwd results in os command injection.
This vulnerability is identified as CVE-2025-34184. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, has been found in Ilevia EVE X1 Server up to 4.7.18.0.eden. This affects an unknown function of the component POST Parameter Handler. The manipulation of the argument db_log leads to information disclosure.
This vulnerability is listed as CVE-2025-34185. The attack may be initiated remotely. There is no available exploit.
A vulnerability, which was classified as critical, was found in Ilevia EVE X1 Server and EVE X5 Server up to 4.7.18.0.eden. This impacts the function system. The manipulation results in improper authentication.
This vulnerability is cataloged as CVE-2025-34186. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as critical was found in Ilevia EVE X1 Server and EVE X5 Server up to 4.7.18.0.eden. The impacted element is an unknown function of the component sudo Handler. Executing manipulation can lead to improper privilege management.
This vulnerability is tracked as CVE-2025-34187. The attack can be launched remotely. No exploit exists.
"Chaotic Deputy" is a set of four vulnerabilities in the chaos engineering platform that many organizations use to test the resilience of their Kubernetes environments.
Researchers uncovered a new supply chain attack targeting the npm registry that impacted over 40 packages belonging to multiple maintainers. Security researchers at Socket uncovered a malicious update to @ctrl/tinycolor, a package with 2.2M weekly downloads on npm. While investigating the case, they discovered it was linked to a larger supply chain attack that compromised […]
A vulnerability categorized as critical has been discovered in WP Import Plugin up to 7.28 on WordPress. The impacted element is the function write_to_customfile of the file customFunction.php. Such manipulation leads to code injection.
This vulnerability is traded as CVE-2025-10057. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Quiz Maker Plugin up to 6.7.0.56 on WordPress. It has been rated as critical. The affected element is an unknown function of the component Header Handler. This manipulation of the argument X-Forwarded-For causes sql injection.
This vulnerability appears as CVE-2025-10042. The attack may be initiated remotely. There is no available exploit.