5.3
CVE-2024-6097 - Absolute Path Traversal Vulnerability
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.
5.1
CVE-2025-1213 - pihome-shc PiHome index.php cross site scripting
A vulnerability was found in pihome-shc PiHome 1.77. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched remotely. The exploit h…
0.0
CVE-2025-1258 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.3
CVE-2025-1210 - code-projects Wazifa System control.php sql injection
A vulnerability classified as critical was found in code-projects Wazifa System 1.0. Affected by this vulnerability is an unknown functionality of the file /controllers/control.php. The manipulation of the argument to leads to sql injection. The attack can be launched remotely. The exploit has been…
5.1
CVE-2025-1209 - code-projects Wazifa System search_resualts.php searchuser cross site scripting
A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is the function searchuser of the file /search_resualts.php. The manipulation of the argument firstname/lastname leads to cross site scripting. It is possible to launch the attack remotely. The exp…
7.1
CVE-2024-11629 - Telerik Document Processing RTF Export of Arbitrary File Path
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.
5.7
CVE-2025-25184 - Possible Log Injection in Rack::CommonLogger
Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.11, 3.0.12, and 3.1.10, Rack::CommonLogger can be exploited by crafting input that includes newline characters to manipulate log entries. The supplied proof-of-concept demonstrates injecting malicious content …
4.1
CVE-2024-11628 - Prototype Pollution in Progress® Telerik® Kendo UI for Vue
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
9.4
CVE-2025-25182 - Stroom Authentication/Authorization Bypass when using AWS ALB
Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with ALB and installed in a way that the applicati…
0.0
CVE-2025-1256 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.