8.3
CVE-2025-36727 - SimpleHelp Inclusion of functionality from untrusted control sphere
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12.
5.3
CVE-2025-8161 - deerwms deer-wms-2 export sql injection
A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. Affected by this vulnerability is an unknown functionality of the file /system/role/export. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be launched remotely. The exploit h…
0.0
CVE-2025-54582 -
Reason: This candidate was issued in error. Valid Netty requests are issued via https://github.com/netty/netty.
8.4
CVE-2014-125119 - WinRAR < 5.00 Filename Spoofing RCE
A filename spoofing vulnerability exists in WinRAR when opening specially crafted ZIP archives. The issue arises due to inconsistencies between the Central Directory and Local File Header entries in ZIP files. When viewed in WinRAR, the file name from the Central Directory is displayed to the user,…
6
CVE-2025-3508 - Certain HP DesignJet products – Information disclosure
Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauthenticated users to view sensitive print job information.
5.1
CVE-2022-4979 - Sitecore XP 7.5 - 10.2, CMS 7.2, and Managed Cloud XSS
A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Update-6 that may allow authenticated Sitecore Shell users to be tricked into executing custom JS code. Managed Cloud Standard customers who run the affected Sitecore Experience Platf…
6.9
CVE-2015-10142 - Sitecore XP < 8.0 and CMS < 7.2 and < 7.5 File Read via Known Path
Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root of the site when the n…
9.3
CVE-2025-34138 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority, as it is a duplicate of CVE-2025-53692 and CVE-2025-53694.
8.7
CVE-2025-34139 - Sitecore XM/XP/XC and Managed Cloud 8.0 - 10.4 Arbitrary File Read
A vulnerability exists in Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud that could allow an unauthenticated attacker to read arbitrary files. This vulnerability affects all Experience Platform topologies (XM, XP, XC) from 8.0 Initial Release…
8.7
CVE-2020-36850 - Sitecore JSS React Sample Application 11.0.0 - 14.0.1 Information Disclosure
An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.