A vulnerability, which was classified as problematic, was found in Fiora Chat Application 1.0.0. This affects an unknown function of the component SVG File Parser. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-56514. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in IMPAQTR Aurora up to 1.35. The impacted element is an unknown function. The manipulation leads to improper control of resource identifiers.
This vulnerability is listed as CVE-2025-59687. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in SPDK Storage Performance Development Kit 25.05. The affected element is an unknown function of the component NVMe-oF Target. Executing manipulation can lead to buffer overflow.
This vulnerability is tracked as CVE-2025-57275. The attack is only possible within the local network. No exploit exists.
It is best practice to apply a patch to resolve this issue.
A vulnerability classified as critical has been found in Kazaar 1.25.12. Impacted is an unknown function of the file /api/v1/org-id/orders/order-id/documents. Performing manipulation of the argument order-id results in privilege escalation.
This vulnerability is identified as CVE-2025-59686. The attack can only be performed from the local network. There is not any exploit available.
A vulnerability described as critical has been identified in Kazaar 1.25.12. This issue affects some unknown processing. Such manipulation of the argument alg leads to privilege escalation.
This vulnerability is referenced as CVE-2025-59685. The attack needs to be initiated within the local network. No exploit is available.
A vulnerability marked as problematic has been reported in DigiSign DigiSigner ONE 1.0.4.60. This vulnerability affects unknown code. This manipulation causes uncontrolled search path.
The identification of this vulnerability is CVE-2025-59684. The attack can only be executed locally. There is no exploit available.
A vulnerability labeled as critical has been found in TOTOLINK X18 9.1.0cu.2053_B20230309. This affects the function setEasyMeshAgentCfg. The manipulation of the argument agentName results in command injection.
This vulnerability was named CVE-2025-61044. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as critical has been detected in TOTOLINK X18 9.1.0cu.2053_B20230309. Affected by this issue is the function setEasyMeshAgentCfg. The manipulation of the argument mac leads to command injection.
This vulnerability is uniquely identified as CVE-2025-61045. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability categorized as critical has been discovered in Splunk Enterprise and Cloud Platform. Affected by this vulnerability is an unknown functionality of the component REST API Call Handler. Executing manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2025-20371. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Splunk Enterprise and Cloud Platform. It has been rated as problematic. Affected is an unknown function. Performing manipulation results in xml entity expansion.
This vulnerability is known as CVE-2025-20369. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in IBM Transformation Extender Advanced 10.0.1. It has been declared as problematic. This impacts an unknown function. Such manipulation leads to sensitive information in log files.
This vulnerability is traded as CVE-2023-50301. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Splunk Enterprise and Enterprise Cloud. It has been classified as problematic. This affects the function change_authentication. This manipulation causes resource consumption.
This vulnerability appears as CVE-2025-20370. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in Splunk Enterprise and Cloud Platform and classified as problematic. The impacted element is an unknown function of the component Error Message Handler. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2025-20368. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability has been found in Splunk Enterprise and Cloud Platform and classified as problematic. The affected element is an unknown function. The manipulation of the argument dataset.command leads to cross site scripting.
This vulnerability is documented as CVE-2025-20367. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in Splunk Enterprise and Cloud Platform. Impacted is an unknown function of the component Search Result Handler. Executing manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2025-20366. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Fiora Chat Application up to 1.0.0. This issue affects some unknown processing of the component SVG File Parser. Performing manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-56515. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as critical was found in Frappe ERPNext 15.57.5. This vulnerability affects the function get_stock_balance_for of the file erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py. Such manipulation of the argument inventory_dimensions_dict leads to sql injection.
This vulnerability is listed as CVE-2025-52041. The attack may be performed from remote. There is no available exploit.
Applying a patch is advised to resolve this issue.
A vulnerability classified as critical has been found in Frappe ERPNext 15.57.5. This affects the function get_material_requests_based_on_supplier of the file erpnext/stock/doctype/material_request/material_request.py. This manipulation of the argument txt causes sql injection.
This vulnerability is tracked as CVE-2025-52039. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to apply a patch to fix this issue.
A vulnerability described as critical has been identified in Frappe ERPNext 15.57.5. Affected by this issue is the function get_blanket_orders of the file erpnext/controllers/queries.py. The manipulation of the argument blanket_order_type results in sql injection.
This vulnerability is identified as CVE-2025-52040. The attack can be executed remotely. There is not any exploit available.
It is best practice to apply a patch to resolve this issue.