7.1
CVE-2025-33137 - IBM Aspera Faspex data modification
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to client-side enforcement of server-side security.
7.1
CVE-2025-33136 - IBM Aspera Faspex data modification
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unauthorized actions on behalf of another user due to improper protection of assumed immutable data.
7.4
CVE-2025-4366 - Request Smuggling Vulnerability in Pingora
A request smuggling vulnerability identified within Pingoraβs proxying framework, pingora-proxy, allows malicious HTTP requests to be injected via manipulated request bodies on cache HITs, leading to unauthorized request execution and potential cache poisoning. Fixed in:Β https://github.com/cloudfβ¦
6.1
CVE-2025-23183 - UBtech β CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
6.9
CVE-2025-5081 - Campcodes Cybercafe Management System adminprofile.php sql injection
A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The expβ¦
4.3
CVE-2025-23182 - UBtech β CWE-203: Observable Discrepancy
CWE-203: Observable Discrepancy
5.3
CVE-2025-2506 -
When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a database configured for replication can execute the pglogical command to obtain read access to replicated tables. When pglogical runs it should verify it iβ¦
8.7
CVE-2025-5080 - Tenda FH451 webExcptypemanFilter stack-based overflow
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFilter of the file /goform/webExcptypemanFilter. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploitβ¦
6.8
CVE-2024-12093 - Improper Validation of Consistency within Input in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.
4.6
CVE-2025-0605 - Weak Authentication in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 16.8 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Group access controls could allow certain users to bypass two-factor authentication requirements.