A vulnerability was found in ASRock RGBLED, A-Tuning, F-Stream and RestartToUEFI and classified as critical. This issue affects some unknown processing in the library AsrDrv101.sys/AsrDrv102.sys of the component Driver. Executing manipulation can lead to improper input validation.
This vulnerability is registered as CVE-2018-10711. The attack needs to be launched locally. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in ASRock RGBLED, A-Tuning, F-Stream and RestartToUEFI. It has been classified as critical. Impacted is an unknown function in the library AsrDrv101.sys/AsrDrv102.sys of the component Driver. The manipulation leads to improper access controls.
This vulnerability is documented as CVE-2018-10712. The attack needs to be performed locally. Additionally, an exploit exists.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Envoy. This issue affects some unknown processing. This manipulation causes session expiration.
This vulnerability is tracked as CVE-2025-55162. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in OpenTelemetry Plugin up to 3.1543.v8446b_92b_cd64 on Jenkins. This vulnerability affects unknown code. The manipulation results in permission issues.
This vulnerability is identified as CVE-2025-58460. The attack can only be performed from the local network. There is not any exploit available.
A vulnerability marked as problematic has been reported in Memos 0.22. This affects an unknown part of the component Upload Attachment Handler. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2025-56761. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability labeled as problematic has been found in HCL Compass up to 2.2.7. Affected by this issue is some unknown functionality. Executing manipulation can lead to storing passwords in a recoverable format.
The identification of this vulnerability is CVE-2025-0280. The attack can only be executed locally. There is no exploit available.
A vulnerability identified as problematic has been detected in Slink 1.4.9. Affected by this vulnerability is an unknown functionality of the component SVG File Upload. Performing manipulation results in cross site scripting.
This vulnerability was named CVE-2025-55944. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as critical has been discovered in Tenda AC8 16.03.34.06. Affected is the function formWifiBasicSet. Such manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-55852. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Figma Desktop 125.6.5 on Windows. It has been rated as critical. This impacts the function child_process.exec of the file manifest.json. This manipulation of the argument build causes command injection.
This vulnerability is handled as CVE-2025-56803. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in LinkedIn Mobile App 4.1.1087.2 on Android. It has been declared as problematic. This affects an unknown function of the component Link Preview Handler. The manipulation of the argument image/title/description results in the ui performs the wrong action.
This vulnerability is known as CVE-2025-56139. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in Git Client Plugin up to 6.3.2 on Jenkins. It has been classified as critical. The impacted element is an unknown function of the component Controller File System Handler. The manipulation leads to permission issues.
This vulnerability is traded as CVE-2025-58458. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability was found in global-build-stats Plugin up to 322.v22f4db_18e2dd on Jenkins and classified as critical. The affected element is an unknown function of the component REST API Endpoint. Executing manipulation can lead to permission issues.
This vulnerability appears as CVE-2025-58459. The attacker needs to be present on the local network. There is no available exploit.
A vulnerability has been found in xwiki-platform up to 16.10.6 and classified as critical. Impacted is an unknown function. Performing manipulation results in relative path traversal.
This vulnerability is reported as CVE-2025-55748. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in Memos 0.22. This issue affects some unknown processing of the component CreateResource Endpoint. Such manipulation leads to path traversal.
This vulnerability is documented as CVE-2025-56760. The attack needs to be performed locally. There is not any exploit available.
A vulnerability, which was classified as critical, has been found in SourceCodester Corona Virus Tracker App India 1.0 on Android. This vulnerability affects the function handleDigest of the file OkHttpClientWrapper.java. This manipulation causes authentication bypass by capture-replay.
This vulnerability is registered as CVE-2025-56608. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability classified as critical was found in Netty. This affects an unknown part. The manipulation results in http request smuggling.
This vulnerability is cataloged as CVE-2025-58056. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in xwiki-platform up to 16.10.6. Affected by this issue is some unknown functionality of the component Webjars API. The manipulation leads to relative path traversal.
This vulnerability is listed as CVE-2025-55747. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Sitecore Experience Manager and Experience Platform up to 9.0. Affected by this vulnerability is an unknown functionality. Executing manipulation can lead to deserialization.
This vulnerability is tracked as CVE-2025-53690. The attack can be launched remotely. No exploit exists.
A vulnerability marked as critical has been reported in Django up to 4.2.23/5.1.11/5.2.5. Affected is the function QuerySet.annotate/QuerySet.alias. Performing manipulation results in sql injection.
This vulnerability is identified as CVE-2025-57833. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.