8.3
CVE-2025-27791 - Collabora Online Vulnerable to Arbitrary File Write
Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, there is a path traversal flaw in handling the CheckFileInfo BaseFileName field returned from WOPI servers. This allows for a file to be written anywhereโฆ
5.4
CVE-2025-24358 - gorilla/csrf CSRF vulnerability due to broken Referer validation
gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior to 1.7.2, gorilla/csrf does not validate the Origin header against an allowlist. Its executes its validation of the Referer header for cross-origin requests only when it believes โฆ
4.9
CVE-2023-5616 - gnome-control-center: Remote login misconfiguration in GNOME Control Center
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
2.1
CVE-2024-42193 - HCL BigFix Web Reports is susceptible to a Man-In-The-Middle (MITM) attack
HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized accesโฆ
5.6
CVE-2024-42189 - HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack
HCL BigFix Web Reports might be subject to a Denial of Service (DoS) attack, due to a potentially weak validation of an API parameter.
4.8
CVE-2024-42200 - HCL BigFix Web Reports is potentially susceptible to a Stored Cross-Site Scripting (XSS) attack
HCL BigFix Web Reports might be subject to a Stored Cross-Site Scripting (XSS) attack, due to a potentially weak validation of user input.
8.5
CVE-2025-3618 - Local Privilege Escalation Vulnerability
A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on the target software.
8.5
CVE-2025-3617 - Local Privilege Escalation in ThinManagerยฎ
A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat actor could inherit eโฆ
7.3
CVE-2025-32780 - BleachBit for Windows Has DLL Untrusted Path Vulnerability
BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerable to a DLL Hijacking vulnerability. By placing a malicious DLL with the name uuid.dll in the folder C:\Users\<username>\AppData\Local\Microsoft\WindowsApps\, an attacker can execโฆ
6.5
CVE-2025-32779 - labsai/eddi Vulnerable to Path Traversal (Zip Slip) in ZIP Import Function
E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. In versions before 5.5.0, an attacker with access to the `/backup/import` API endpoint can write arbitrary files to locations outside the intended extraction directory due to a Zip Slip vulnerability. Altโฆ