A vulnerability was found in WikkiTikkiTavi 0.5/0.10/0.20. It has been rated as critical. This affects an unknown part of the file conflict.php. This manipulation of the argument TemplateDir causes improper privilege management.
This vulnerability is tracked as CVE-2002-2106. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is advised.
A vulnerability labeled as critical has been found in Matt Wright FormMail up to 1.9. Impacted is an unknown function of the component Referer Checker. Executing manipulation of the argument HTTP_REFERER can lead to authentication bypass by spoofing.
This vulnerability is registered as CVE-2002-2109. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as critical, has been found in Artekopia Netjuke up to 1.0 B6. Affected is the function eval. Performing manipulation of the argument section results in improper privilege management.
This vulnerability is known as CVE-2002-2114. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Hyper NIKKI System up to 0.8/2.10. Affected by this vulnerability is an unknown functionality. Executing manipulation can lead to basic cross site scripting.
This vulnerability is handled as CVE-2002-2115. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in SurfControl Superscout Email Filter 3.5.1. The affected element is an unknown function of the component SMTP Proxy. Executing manipulation of the argument HELO/RCPT TO can lead to memory corruption.
This vulnerability is tracked as CVE-2002-2121. The attack can be launched remotely. No exploit exists.
A vulnerability labeled as critical has been found in Gallery 1.3.2. This affects an unknown function of the file publish_xp_docs.php. The manipulation of the argument GALLERY_BASEDIR results in improper privilege management.
This vulnerability is cataloged as CVE-2002-2123. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in w-Agora 4.1.5. This affects an unknown part of the file editform.php. The manipulation of the argument File leads to path traversal.
This vulnerability is traded as CVE-2002-2128. An attack has to be approached locally. There is no exploit available.
A vulnerability, which was classified as problematic, was found in w-Agora 4.1.5. This vulnerability affects unknown code of the file editform.php of the component Form Handler. The manipulation results in basic cross site scripting.
This vulnerability is known as CVE-2002-2129. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability was found in PEEL 1.0b. It has been rated as critical. This affects an unknown function of the file haut.php. The manipulation of the argument dirroot leads to improper privilege management.
This vulnerability is referenced as CVE-2002-2134. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability classified as problematic has been found in ISC Kea up to 2.7.9/3.0.0/3.1.0. Affected by this issue is some unknown functionality of the component DHCPv4 Handler. Performing manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-40779. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability was found in Cisco Unified Computing System. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the component Web-based Management Interface/CLI. Performing manipulation results in os command injection.
This vulnerability is known as CVE-2025-20294. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
Also: Netskope's High-Stakes IPO, How AI Sovereignty Threatens Our Shared Reality In this week's update, four ISMG editors discussed explosive whistleblower claims about alleged mishandling of Americans' sensitive U.S. Social Security data, Netskope's push for an initial public offering and the global fight over the geopolitical sovereignty of artificial intelligence platforms.
Absolute Dental Says Breach Involved Third-Party Managed Services Firm A Nevada dental practice is notifying more than 1.2 million individuals of a hacking incident that compromised sensitive health and personal information. The incident involved "inadvertent execution of a malicious version of a legitimate software tool," said Absolute Dental.
Defense Department Suspends, Reviews Microsoft 'Digital Escorts' Program The Pentagon is reviewing Microsoft's decade-long use of "digital escorts" - U.S.-based staff who review code from Chinese engineers - into military cloud systems, a workaround now deemed a "breach of trust" that may have exposed sensitive but unclassified government data.