9.4
CVE-2025-8426 - Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-…
Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose sensitive information or to create a denial-of-service condition on affected installations of Marvell QConvergeConsole.…
6.9
CVE-2025-54833 - OPEXUS FOIAXpress Public Access Link (PAL) account-lockout and CAPTCHA protection bypass
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account-lockout and CAPTCHA protections. Unauthenticated remote attackers can more easily brute force passwords.
6.9
CVE-2025-54834 - OPEXUS FOIAXpress Public Access Link (PAL) unauthenticated username enumeration
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/CreateRequest.aspx endpoint to check for the existence of valid usernames. There are no rate-limiting mechanisms in place.
5.3
CVE-2025-54832 - OPEXUS FOIAXpress Public Access Link (PAL) state and territory list unauthorized modification
OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of states and territories.
6.9
CVE-2025-8409 - code-projects Vehicle Management filter.php sql injection
A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /filter.php. The manipulation of the argument from leads to sql injection. The attack can be launched remotely. The exploit has b…
6.9
CVE-2025-46809 - Multi Linux Manager epxoses the plain text HTTP Proxy user:password in logs
A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. This issue affects Container suse/manager/4.3/proxy-httpd:4.3.16.9.67.1: from ? before 4.3.33-150400.3.55.2; Container suse/manager/5.0/x86_64/proxy-httpd:5.0.5.7.23.1: from ? before…
6.9
CVE-2025-8408 - code-projects Vehicle Management filter1.php sql injection
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. Affected is an unknown function of the file /filter1.php. The manipulation of the argument vehicle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclos…
9.3
CVE-2013-10037 - WebTester 5.x install2.php Unauthenticated Command Execution
An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafte…
9.2
CVE-2014-125126 - Simple E-Document Arbitrary File Upload RCE
An unrestricted file upload vulnerability exists in Simple E-Document versions 3.0 to 3.1 that allows an unauthenticated attacker to bypass authentication by sending a specific cookie header (access=3) with HTTP requests. The application’s upload mechanism fails to restrict file types and does not …
8.7
CVE-2013-10035 - ProcessMaker Open Source < 2.5.2 neoclassic Skin PHP Code Execution
A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin. An authenticated user can execute arbitrary PHP code via multiple endpoints, including appFolderAjax.php, casesStartPage_Ajax.php, and cases_SchedulerGetPlugins.php, by supplying…