5.1
CVE-2025-56802 -
The Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing attackers with local access to decrypt sensitive application data stored in %APPDATA%. A different vulnerability than CVE-2025-56801. NOTE: the Supplier's position is thβ¦
6.1
CVE-2025-60933 -
Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Descripβ¦
8.8
CVE-2025-52079 -
The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Unverified Password Change via crafted POST request to /get_set.ccp.
6.5
CVE-2025-56799 -
Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.
5.3
CVE-2025-59438 -
Mbed TLS through 3.6.4 has an Observable Timing Discrepancy.
6.1
CVE-2025-57521 -
Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without validating its digital signature or verifying its authenticity. A local attacker can exploit this behavior by placing a maβ¦
6.5
CVE-2025-61194 -
daicuocms V1.3.13 contains a SQL injection vulnerability in the file library\think\db\Builder.php.
6.1
CVE-2025-60934 -
Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee Notes, title, or description parameters. The patched β¦
6.5
CVE-2025-61181 -
daicuocms V1.3.13 contains an arbitrary file upload vulnerability in the image upload feature.
6.5
CVE-2025-60790 -
ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.