Unsigned Order Overturns District Court Injunction The U.S. Supreme Court granted Friday a Trump administration cost-cutting effort known as the "Department of Government Efficiency" access to data on Americans held at the Social Security Administration. Two liberal justices accused their conservative colleagues of a double standard.
A vulnerability has been found in OpenMRS 2.4.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/users/user.form of the component GET Request Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2025-25928. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Alludo Parallels Desktop up to 19.4.1/20.2.1 on macOS. This affects an unknown part of the component VM Creation Routine. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2025-30074. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Koha up to 22.11.23/23.11.11/24.05.06/24.11.01 and classified as problematic. Affected by this issue is some unknown functionality of the file tools/scheduler.pl. The manipulation of the argument report leads to os command injection.
This vulnerability is handled as CVE-2025-30076. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in boxdot gurk-rs up to 0.6.3. It has been classified as problematic. This affects an unknown part. The manipulation leads to improper neutralization of escape, meta, or control sequences.
This vulnerability is uniquely identified as CVE-2025-30089. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in ROADCAM X3 App on Android. It has been classified as problematic. This affects an unknown part. The manipulation leads to hard-coded credentials.
This vulnerability is uniquely identified as CVE-2025-30123. An attack has to be approached locally. There is no exploit available.
A vulnerability has been found in onosproject onos-lib-go 0.10.28 and classified as critical. Affected by this vulnerability is the function GetBitString of the component asn1/aper. The manipulation of the argument zeronumBits leads to improper validation of array index.
This vulnerability is known as CVE-2025-30077. Local access is required to approach this attack. There is no exploit available.
A vulnerability was found in Microsoft Windows 2000. It has been rated as critical. This issue affects some unknown processing of the file telnet.exe of the component NTLM Authentication. The manipulation leads to improper privilege management.
The identification of this vulnerability is CVE-2000-0834. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in All Video Gallery Plugin. Affected by this issue is some unknown functionality. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2012-6653. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as very critical has been found in Oracle Agile PLM 9.3.3/9.3.4/9.3.5. Affected is an unknown function of the component Oracle WebLogic Server. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2019-2725. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Cutephp CuteNews 1.4.1. It has been rated as problematic. This issue affects some unknown processing of the file show_archives.php. The manipulation of the argument template leads to path traversal.
The identification of this vulnerability is CVE-2005-3507. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in Cutephp CuteNews 1.4.0. It has been classified as critical. This affects an unknown part of the file inc/shows.inc.php of the component Protection Feature. The manipulation of the argument HTTP_CLIENT_IP leads to denial of service.
This vulnerability is uniquely identified as CVE-2005-3010. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability has been found in Vortexgroup Light Alloy up to 4.7.2 and classified as very critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2013-6874. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Apple iTunes up to 12.6.1 on Windows. Affected is an unknown function of the component WebKit. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2017-7061. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in WpEvently Plugin up to 4.4.2 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2025-5568. The attack can be initiated remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Social Sharing Plugin Plugin up to 3.3.75 on WordPress. This affects an unknown part. The manipulation of the argument heateor_mastodon_share leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-5528. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in LTL Freight Quotes Plugin up to 1.0.11/2.1.10/2.2.6 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument expiry_date leads to cross site scripting.
This vulnerability is handled as CVE-2025-5303. The attack may be launched remotely. There is no exploit available.