A vulnerability was found in O2OA up to 10.0-410. It has been rated as problematic. Affected is an unknown function of the file /x_query_assemble_designer/jaxrs/importmodel of the component Personal Profile Page. Performing manipulation of the argument description/applicationName/queryName results in cross site scripting.
This vulnerability is known as CVE-2025-9737. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability categorized as problematic has been discovered in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_tipo_ensino_cad.php. Executing manipulation of the argument nm_tipo can lead to cross site scripting.
This vulnerability is handled as CVE-2025-9738. The attack can be executed remotely. Additionally, an exploit exists.
A vulnerability described as problematic has been identified in FloweRS 2.0. This affects an unknown function of the file cas.php. Such manipulation of the argument rok leads to basic cross site scripting.
This vulnerability is referenced as CVE-2007-2308. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in Wsdeluxe FMDeluxe 2.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument ID results in cross site scripting.
This vulnerability is cataloged as CVE-2007-6162. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability has been found in Fizzle 0.5 and classified as problematic. Impacted is an unknown function of the component URI Handler. The manipulation leads to basic cross site scripting.
This vulnerability is listed as CVE-2007-1678. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability described as critical has been identified in Sinato jmuffin. Affected is an unknown function of the file html/php/detail.php. Such manipulation leads to code injection.
This vulnerability is listed as CVE-2007-2262. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability has been found in Firesoft and classified as critical. This affects an unknown part of the file includes/class/class_tpl.php of the component Cache. The manipulation of the argument cache_file leads to code injection.
This vulnerability is uniquely identified as CVE-2007-4458. The attack is possible to be carried out remotely. Moreover, an exploit is present.
A vulnerability identified as critical has been detected in Oracle VM VirtualBox 7.1.10. The impacted element is an unknown function of the component Core. Performing manipulation results in improper authorization.
This vulnerability is identified as CVE-2025-53030. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.
A vulnerability identified as problematic has been detected in TianoCore EDK2 up to edk2-stable202502. This impacts an unknown function of the component BIOS. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2024-38805. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability classified as critical has been found in Intel Processors. Impacted is an unknown function. Performing manipulation results in improper isolation or compartmentalization.
This vulnerability is identified as CVE-2025-20109. The attack is only possible with local access. There is not any exploit available.
A vulnerability classified as critical has been found in Intel Xeon Processor. Affected by this vulnerability is an unknown functionality. This manipulation causes memory corruption.
The identification of this vulnerability is CVE-2025-20053. The attack can only be executed locally. There is no exploit available.
A vulnerability classified as critical was found in HtmlUnit up to 3.8.x. Affected is an unknown function of the component XSTL Handler. Executing manipulation can lead to code injection.
This vulnerability is tracked as CVE-2023-49093. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability was found in Oracle WebLogic Server 12.2.1.4.0/14.1.1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component Centralized Thirdparty Jars. Executing manipulation can lead to code injection.
The identification of this vulnerability is CVE-2023-49093. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as critical was found in vim up to 9.1.1399. Affected is the function tuple_unref. The manipulation results in use after free.
This vulnerability is cataloged as CVE-2025-55157. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in libcsp 2.0. It has been classified as critical. The affected element is the function csp_eth_init. The manipulation of the argument ifname leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-51823. The attack can only be initiated within the local network. No exploit exists.
It is suggested to install a patch to address this issue.
A vulnerability described as critical has been identified in Sourcecraft Networking Utils 1.0. Affected is an unknown function of the file networking_utils.php of the component ping Utility. Executing manipulation of the argument address can lead to improper privilege management.
This vulnerability is tracked as CVE-2002-1971. The attack can be launched remotely. No exploit exists.
A vulnerability categorized as critical has been discovered in Microsoft SQL Server up to 2000 SP2. This impacts the function sp_MSSetServerProperties/sp_MSsetalertinfo of the component Stored Procedure. Such manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2002-1981. The attack can be launched remotely. No exploit exists.
A vulnerability classified as critical was found in Working Resources Inc. Badblue Personal 1.7.3. Affected by this issue is the function CHttpServer::OnParseError of the file isapi.cpp. The manipulation results in memory corruption.
This vulnerability is cataloged as CVE-2002-1973. The attack may be launched remotely. Furthermore, there is an exploit available.
Upgrading the affected component is advised.