5.5
CVE-2024-41750 - IBM SmartCloud Analytics - Log Analysis security bypass
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.
7
CVE-2025-54296 - Extension - mooj.org - Stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla
A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.
6.2
CVE-2024-40682 - IBM SmartCloud Analytics - Log Analysis denial of service
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local user to cause a denial of service due to improper validation of specified type of input.
8.5
CVE-2025-50127 - Extension - dj-extensions.com - SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla
A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands.
5.4
CVE-2024-40686 - IBM SmartCloud Analytics - Log Analysis HOST header injection
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including crossβ¦
5.5
CVE-2024-41751 - IBM SmartCloud Analytics - Log Analysis security bypass
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 could allow a local, authenticated attacker to bypass client-side enforcement of security to manipulate data.
6.4
CVE-2025-27930 - Stored XSS
Zohocorp ManageEngine Applications Manager versionsΒ 176600 and prior are vulnerable to stored cross-site scripting in theΒ File/Directory monitor.
4.8
CVE-2025-53882 - The logrotate configuration in the python-mailman of openSUSE allows the mailman user to sent SIGHUβ¦
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3 package allows the mailman user to sent SIGHUP to arbitrary processes.Β This issue affects openSUSE Tumbleweed: from ? before 3.3.10-2.1.
9.8
CVE-2025-41687 - Weidmueller: Unauthenticated Stack-Based Buffer Overflow in u-link Management API
An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices.
8.8
CVE-2025-41684 - Weidmueller: Root Command Injection via Unsanitized Input in tls_iotgen_setting Endpoint
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).