6.2
CVE-2023-7312 - Nagios Fusion < 4.2.0 Email Settings Stored XSS via SMTP/sendmail
Nagios Fusion versions prior toย 4.2.0 contain a stored cross-site scripting (XSS) vulnerability whenย adding or configuring Email Settings. Unsanitized user input can be stored and later rendered in the administrative UI, causing JavaScript to execute in the browser of any user who views the affecteโฆ
8.6
CVE-2025-34269 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60424.
9.3
CVE-2025-34249 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate ofย CVE-2025-60425.
9.3
CVE-2023-7325 - Mingyu Operations and Maintenance Audit and Risk Control System xmlrpc.sock SSRF
Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The product accepts specially crafted XML-RPC requests that can be used to instruct the server to connect to internal unix sโฆ
9.3
CVE-2021-4461 - Seeyon Zhiyuan OA Web Application System < 7.0 SP1 Authentication Bypass
Seeyon Zhiyuan OA Web Application System versions up to and including 7.0 SP1ย improperly decode and parse the `enc` parameter in thirdpartyController.do. The decoded map values can influence session attributes without sufficient authentication/authorization checks, enabling attackers to assign a seโฆ
8.8
CVE-2025-8850 - Insecure API Design in danny-avila/librechat
In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA without requiring a valid OTP or backup code, bypassing the intended verification process. This vulnerability occurs because the backend doโฆ
8.6
CVE-2025-3356 - IBM Tivoli Monitoring is vulnerable to unauthenticated file read and write operations
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system.
7.5
CVE-2025-3355 - IBM Tivoli Monitoring is vulnerable to unauthenticated file read and write operations
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
7.2
CVE-2025-36137 - IBM Sterling Connect:Direct for UNIX command execution
IBM Sterling Connect Direct for Unix 6.2.0.7 through 6.2.0.9 iFix004, 6.4.0.0 through 6.4.0.2 iFix001, and 6.3.0.2 through 6.3.0.5 iFix002 incorrectly assigns permissions for maintenance tasks to Control Center Director (CCD) users that could allow a privileged user to escalate their privileges furโฆ
0.0
CVE-2025-12532 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.