A vulnerability classified as critical has been found in Wavlink AC3000 M33A8.V5030.210505. The affected element is the function qos_settings of the file qos.cgi. The manipulation of the argument sel_mode leads to buffer overflow.
This vulnerability is referenced as CVE-2024-39803. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability has been found in goauthentik authentik and classified as critical. Impacted is an unknown function of the component Web Interface/API. The manipulation leads to session fixiation.
This vulnerability is referenced as CVE-2025-29928. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition and classified as problematic. This affects an unknown part of the component FRS REST Endpoint. Executing manipulation can lead to incorrect authorization.
The identification of this vulnerability is CVE-2025-30209. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. It has been classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2025-29766. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. It has been declared as problematic. This issue affects some unknown processing. The manipulation results in cross-site request forgery.
This vulnerability is identified as CVE-2025-29929. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. It has been rated as problematic. Impacted is an unknown function of the component RSS Widget. This manipulation causes improper neutralization of encoded uri schemes in a web page.
This vulnerability is tracked as CVE-2025-30203. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability marked as problematic has been reported in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. This impacts an unknown function of the component REST API. The manipulation leads to incorrect authorization.
This vulnerability is documented as CVE-2025-30155. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in Bitdefender GravityZone Update Server. It has been rated as critical. The affected element is an unknown function of the component Outbound Requests Handler. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2025-2245. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Checkmk up to 2.1.0p50/2.2.0p38/2.3.0p24. Affected by this issue is some unknown functionality of the component RestAPI. This manipulation causes improper neutralization of delimiters.
This vulnerability is tracked as CVE-2024-38865. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in taisan tarzan-cms up to 1.0.0. This impacts the function Upload of the file /admin#themes of the component Add Theme Handler. Executing manipulation can lead to deserialization.
This vulnerability appears as CVE-2025-1113. The attack may be performed from a remote location. In addition, an exploit is available.
A vulnerability was found in goauthentik authentik up to 2024.10.3. It has been declared as problematic. The affected element is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2024-11623. The attack may be performed from a remote location. There is no available exploit.
It is recommended to upgrade the affected component.