4.8
CVE-2025-29790 - Contao allows cross-site scripting through SVG uploads
Contao is an Open Source CMS. Users can upload SVG files with malicious code, which is then executed in the back end and/or front end. This vulnerability is fixed in Contao 4.13.54, 5.3.30, or 5.5.6.
8.6
CVE-2025-24801 - GLPI allows authenticated remote code execution
GLPI is a free asset and IT management software package. An authenticated user can upload and force the execution of *.php files located on the GLPI server. This vulnerability is fixed in 10.0.18.
7.5
CVE-2025-24799 - GLPI allows unauthenticated SQL injection through the inventory endpoint
GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the inventory endpoint. This vulnerability is fixed in 10.0.18.
8.2
CVE-2025-21619 - GLPI allows SQL injection through the rules configuration
GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the rules configuration forms. This vulnerability is fixed in 10.0.18.
0.0
CVE-2025-2504 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
9.6
CVE-2024-56347 - IBM AIX command execution
IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
10
CVE-2024-56346 - IBM AIX command execution
IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.
7.8
CVE-2025-27688 -
Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
4.8
CVE-2025-2491 - Dromara ujcms Edit Template File Page WebFileTemplateController.java update cross site scripting
A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit Template File Page. The manipulation leads to cross site scripting. It is poโฆ
4.1
CVE-2024-49822 - IBM QRadar Advisor server-side request forgery
IBM QRadar Advisor 1.0.0 through 2.6.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.