10
CVE-2025-48983 -
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
7.8
CVE-2025-48982 -
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.
6.3
CVE-2025-27208 -
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context oโฆ
8.8
CVE-2025-48984 -
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
10
CVE-2025-52665 -
A malicious actor with access to the management network could exploit a misconfiguration in UniFiโs door access application, UniFi Access, that exposed a management API without proper authentication. This vulnerability was introduced in Version 3.3.22 and was fixed in Version 4.0.21 and later.ย Aโฆ
7.3
CVE-2025-52663 -
A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintentionally enabled. This issue could allow an attacker with access to the UniFi Talk management network to invoke internal debug operations through the device API. Affected Productโฆ
6.5
CVE-2025-48980 -
In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method.
8.8
CVE-2025-52664 -
SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users
5.1
CVE-2011-10037 - Nagios XI < 2011R1.9 XSS via xiwindow Variables Affecting Permalinks
Nagios XI versions prior toย 2011R1.9ย are vulnerable to cross-site scripting (XSS) viaย the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the contโฆ
5.1
CVE-2021-47697 - Nagios XI < 5.8.0 XSS via Views URL Handling
Nagios XI versions prior toย 5.8.0ย are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.