4.8
CVE-2025-14698 - atlaszz AI Photo Team Galleryit App gallery.photogallery.pictures.vault.album path traversal
A weakness has been identified in atlaszz AI Photo Team Galleryit App 1.3.8.2 on Android. This affects an unknown part of the component gallery.photogallery.pictures.vault.album. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been made available toβ¦
6.3
CVE-2025-14697 - Shenzhen Sixun Software Sixun Shanghui Group Business Management System ExportFiles file access
A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this issue is some unknown functionality of the file /ExportFiles/. The manipulation results in files or directories accessible. The attack may be launched remotely.β¦
6.9
CVE-2025-14696 - Shenzhen Sixun Software Sixun Shanghui Group Business Management System UpdatePasswordBatch passworβ¦
A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The manipulation leads to weak password recovery. The attack may be initiβ¦
5.3
CVE-2025-14695 - SamuNatsu HaloBot Inter-plugin API index.js html_renderer dynamically-managed code resources
A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.js of the component Inter-plugin API. Executing manipulation of the argument action can lead to dynamically-managed codeβ¦
5.1
CVE-2025-14694 - ketr JEPaaS readAllPostil sql injection
A vulnerability was found in ketr JEPaaS up to 7.2.8. This impacts the function readAllPostil of the file /je/postil/postil/readAllPostil. Performing a manipulation of the argument keyWord results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be β¦
7
CVE-2025-14693 - Ugreen DH2100+ USB symlink
A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads to symlink following. The attack can be executed directly on the physical device. The exploit has been disclosed to the public and may be used. It is β¦
6.1
CVE-2023-36337 -
A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
4.7
CVE-2025-67809 -
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A hardcoded Flickr API key and secret are present in the publicly accessible Flickr Zimlet used by Zimbra Collaboration. Because these credentials are embedded directly in the Zimlet, any unauthorized party could retrieve them andβ¦
8.2
CVE-2025-65742 -
An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to obtain sensitive information and execute a full account takeover via a crafted API request.
8.8
CVE-2024-44598 -
FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.