6.5
CVE-2025-36092 - IBM Business Automation Insights improper input validation
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of service due to the improper validation of input length.
4.3
CVE-2025-36091 - IBM Business Automation Insights unverified ownership
IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards to become inaccessible to legitimate users due to invalid ownership assignment.
8.5
CVE-2025-11761 - HP Client Management Script Library β Security Update
A potential security vulnerability has been identified in the HP Client Management Script Library software, which might allow escalation of privilege during the installation process. HP is releasing software updates to mitigate the potential vulnerability.
9.8
CVE-2025-8900 - Doccure Core < 1.5.4 - Unauthenticated Privilege Escalation
The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'user_type' field. This makes it possible for unauthenticated attackerβ¦
5.3
CVE-2025-64294 - WordPress WP Snow Effect plugin <= 1.1.19 - Broken Access Control vulnerability
Missing Authorization vulnerability in d3wp WP Snow Effect wp-snow-effect allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Snow Effect: from n/a through <= 1.1.19.
5.3
CVE-2025-12626 - jeecgboot jeewx-boot WxActGoldeneggsPrizesController.java getImgUrl path traversal
A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects the function getImgUrl of the file WxActGoldeneggsPrizesController.java. Performing manipulation of the argument imgurl results in path traversal. Remote exploitation of the attaβ¦
9.9
CVE-2025-0987 - IDOR in CB Project's CVLand
Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection.This issue affects CVLand: from 2.1.0 through 20251103.Β NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
7.1
CVE-2025-48397 -
The privileged user could log in without sufficient credentials after enabling an application protocol.Β This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).
2.3
CVE-2025-12623 - fushengqian fuint Authentication Token ClientSignController.java authorization
A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this issue is some unknown functionality of the file fuint-application/src/main/java/com/fuint/module/clientApi/controller/ClientSignController.java of the component Authentication Token β¦
8.3
CVE-2025-48396 -
Arbitrary code executionΒ is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004).