A vulnerability, which was classified as critical, was found in Rocket TRUfusion Enterprise up to 7.10.4.0. This affects an unknown part of the file /trufusionPortal/getProjectList. Executing manipulation of the argument COOKIEID can lead to use of hard-coded cryptographic key
.
This vulnerability appears as CVE-2025-27223. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as critical, has been found in BAE SOCET GXP. Affected by this issue is some unknown functionality of the component Job Service. Performing manipulation results in improper authentication.
This vulnerability is reported as CVE-2025-54968. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in FRRouting FRR up to 10.4.1. Affected by this vulnerability is the function show_vty_ext_link_adj_sid of the file ospf_ext.c of the component OSPF Packet Handler. Such manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2025-61102. The attack requires being on the local network. There is not any exploit available.
Applying a patch is advised to resolve this issue.
A vulnerability classified as problematic has been found in FRRouting FRR up to 10.4.1. Affected is the function show_vty_link_info of the file ospf_ext.c of the component OSPF Packet Handler. This manipulation causes null pointer dereference.
This vulnerability is registered as CVE-2025-61105. The attack requires access to the local network. No exploit is available.
It is recommended to apply a patch to fix this issue.
A vulnerability described as problematic has been identified in FRRouting FRR up to 10.4.1. This impacts the function show_vty_ext_link_rmt_itf_addr of the file ospf_ext.c of the component OSPF Packet Handler. The manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2025-61101. The attack must originate from the local network. There is no exploit available.
It is best practice to apply a patch to resolve this issue.
A vulnerability marked as problematic has been reported in Liferay Portal and DXP. This affects an unknown function of the component Page Administration. The manipulation of the argument _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect leads to open redirect.
This vulnerability is listed as CVE-2025-62253. The attack may be initiated remotely. There is no available exploit.
A vulnerability labeled as problematic has been found in FRRouting FRR up to 10.4.1. The impacted element is the function ospf_opaque_lsa_dump of the file ospf_opaque.c. Executing manipulation can lead to null pointer dereference.
This vulnerability is tracked as CVE-2025-61100. The attack is only possible within the local network. No exploit exists.
It is advisable to implement a patch to correct this issue.
A vulnerability identified as problematic has been detected in FRRouting FRR up to 10.4.1. The affected element is the function opaque_info_detail of the file ospf_opaque.c of the component LS Update Packet Handler. Performing manipulation results in null pointer dereference.
This vulnerability is identified as CVE-2025-61099. The attack can only be performed from the local network. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.
A vulnerability categorized as critical has been discovered in IBM QRadar SIEM up to 7.5.0 UP13 IF02. Impacted is an unknown function. Such manipulation leads to incorrect privilege assignment.
This vulnerability is referenced as CVE-2025-36007. The attack can only be performed from a local environment. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Educare ERP 1.0 2025-04-22. It has been rated as critical. This issue affects some unknown processing of the component Endpoint. This manipulation causes improper authorization.
The identification of this vulnerability is CVE-2025-60982. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Rocket TRUfusion Enterprise up to 7.10.4.0. It has been declared as problematic. This vulnerability affects unknown code of the file /trufusionPortal/jsp/internal_admin_contact_login.jsp of the component Endpoint. The manipulation results in information disclosure.
This vulnerability was named CVE-2025-27225. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in Liferay Portal and DXP. It has been classified as critical. This affects an unknown part of the component API. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2025-62259. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in Liferay Portal and DXP and classified as problematic. Affected by this issue is some unknown functionality of the component Headless API. Executing manipulation can lead to resource consumption.
This vulnerability is handled as CVE-2025-62260. The attack can be executed remotely. There is not any exploit available.
A vulnerability has been found in THM-Health PILOS up to 4.7.x and classified as critical. Affected by this vulnerability is an unknown functionality. Performing manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is known as CVE-2025-62523. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, was found in BAE SOCET GXP 4.6.0.2. Affected is an unknown function of the component XML File Handler. Such manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-54967. The attack may be launched remotely. Furthermore, there is an exploit available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in IBM QRadar SIEM up to 7.5.0 UP13 IF02. This impacts an unknown function of the component Web UI. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-36170. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in IBM QRadar SIEM up to 7.5.0 UP13 IF02. This affects an unknown function. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2025-36138. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability described as critical has been identified in tlocke pg8000 1.31.4. The affected element is the function pg8000.native.literal. Executing manipulation can lead to sql injection.
This vulnerability is registered as CVE-2025-61385. It is possible to launch the attack remotely. No exploit is available.
Applying a patch is advised to resolve this issue.