4.8
CVE-2025-11019 - Total.js CMS Files Menu cross site scripting
A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Menu. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
3.7
CVE-2025-36326 - IBM Controller information disclosure
IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies.
7.5
CVE-2025-36274 - IBM Aspera HTTP Gateway information disclosure
IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user.
6.1
CVE-2025-6396 - XSS in Webbeyaz's web site
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webbeyaz Website Design Website Software allows Cross-Site Scripting (XSS).This issue affects Website Software: through 2025.07.14.
6.9
CVE-2025-11018 - Four-Faith Water Conservancy Informatization Platform download.do;usrlogout.do.do path traversal
A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of the file /sysRole/index.do/../../generalReport/download.do;usrlogout.do.do. Executing manipulation of the argument fileName can lead to path traversal. It is possible to launch thβ¦
4.8
CVE-2025-11017 - OGRECave Ogre OgreLogManager.cpp stream null pointer dereference
A vulnerability was detected in OGRECave Ogre up to 14.4.1. The impacted element is the function Ogre::LogManager::stream of the file /ogre/OgreMain/src/OgreLogManager.cpp. Performing manipulation of the argument mDefaultLog results in null pointer dereference. The attack must be initiated from a lβ¦
5.3
CVE-2025-11016 - kalcaddle kodbox index.class.php fileOut path traversal
A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileOut of the file app/controller/explorer/index.class.php. Such manipulation of the argument path leads to path traversal. The attack may be performed from remote. The exploit has beβ¦
4.8
CVE-2025-11015 - OGRECave Ogre OgreSTBICodec.cpp encode mismatched memory management routines
A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the file /ogre/PlugIns/STBICodec/src/OgreSTBICodec.cpp. This manipulation causes mismatched memory management routines. The attack is restricted to local execution. The exploit has been β¦
5.3
CVE-2025-11025 - Information Disclosure in Vimeosoft Information Technologies' Vimesoft Corporate Messaging Platform
Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. Vimesoft Corporate Messaging Platform allows Retrieve Embedded Sensitive Data.This issue affects Vimesoft Corporate Messaging Platform: from V1.3.0 before V2.0.0.
7
CVE-2025-9267 -
In Seagate Toolkit on Windows aΒ vulnerability exists in the Toolkit Installer prior toΒ versions 2.35.0.6 where it attempts to load DLLs from the current working directory without validating their origin or integrity. This behavior can be exploited by placing a malicious DLL in the same directory asβ¦