5.1
CVE-2025-9143 - Scada-LTS mailing_lists.shtm cross site scripting
A security flaw has been discovered in Scada-LTS 2.7.8.1. This affects an unknown part of the file mailing_lists.shtm. The manipulation of the argument name/userList/address results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public anβ¦
5.3
CVE-2025-43739 -
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.16 and 7.4 GA through update 92 allow any authenticated user to modify the content of emails sent tβ¦
6.4
CVE-2024-45062 -
A stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer that supports IPP-over-USB can cause a buffer overflow which can lead to a arbitrary code execution in a privileged service. To trigger the vulnerability, a malicious device would neβ¦
5.3
CVE-2025-9140 - Shanghai Lingdang Information Technology Lingdang CRM tabdetail_moduleSave.php sql injection
A vulnerability was identified in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.4.7. Affected by this issue is some unknown functionality of the file /crm/crmapi/erp/tabdetail_moduleSave.php. The manipulation of the argument getvaluestring leads to sql injection. It is possible toβ¦
4.3
CVE-2025-4690 - AngularJS 'linky' filter ReDoS
A regular expression used by AngularJS'Β linky https://docs.angularjs.org/api/ngSanitize/filter/linky Β filter to detect URLs in input text is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted input, this can cause a Regular expression Denial of Service (ReDoSβ¦
8.5
CVE-2025-4046 - Missing Authorization in Lexmark Cloud Services badge management
A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization
8.2
CVE-2025-4044 - XML External Entity Injection vulnerability in various Lexmark Universal Drivers
Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL.
4.6
CVE-2025-43740 -
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.3.120 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.8, 2025.Q1.0 through 2025.Q1.15, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13 and 2024.Q1.9 through 2024.Q1.19 allows aβ¦
5.3
CVE-2025-9139 - Scada-LTS WatchListDwr.init.dwr information disclosure
A vulnerability was determined in Scada-LTS 2.7.8.1. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/dwr/call/plaincall/WatchListDwr.init.dwr. Executing manipulation can lead to information disclosure. The attack may be performed from a remote location. The exploitβ¦
5.1
CVE-2025-9138 - Scada-LTS new cross site scripting
A vulnerability was found in Scada-LTS 2.7.8.1. Affected is an unknown function of the file pointHierarchy/new/. Performing manipulation of the argument Title results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The β¦