8.3
CVE-2025-26508 - Certain HP LaserJet Pro, HP LaserJet Enterprise, HP LaserJet Managed Printers โ Potential Remote Coโฆ
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
6.3
CVE-2025-26507 - Certain HP LaserJet Pro, HP LaserJet Enterprise, HP LaserJet Managed Printers โ Potential Remote Coโฆ
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
9.2
CVE-2025-26506 - Certain HP LaserJet Pro, HP LaserJet Enterprise, HP LaserJet Managed Printers โ Potential Remote Coโฆ
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
8.7
CVE-2025-25295 - Label Studio has a Path Traversal Vulnerability via image Field
Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to 1.0.10 allows unauthorized file access outside the intended directory structure. The flaw exists in the VOC, COCO and YOLO export functionalities. These functions invoke a `downloโฆ
8.3
CVE-2025-25206 - Incorrect input validation could allow an authenticated user to read sensitive information
eLabFTW is an open source electronic lab notebook for research labs. Prior to version 5.1.15, an incorrect input validation could allow an authenticated user to read sensitive information, including login token or other content stored in the database. This could lead to privilege escalation if cookโฆ
6.3
CVE-2025-25204 - `gh attestation verify` returns incorrect exit code during verification if no attestations are presโฆ
`gh` is GitHubโs official command line tool. Starting in version 2.49.0 and prior to version 2.67.0, under certain conditions, a bug in GitHub's Artifact Attestation cli tool `gh attestation verify` causes it to return a zero exit status when no attestations are present. This behavior is incorrect:โฆ
7.3
CVE-2024-8893 -
Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500โXS allows anyone in physical proximity to the device to fully access the web interface of the inverter via WiโFi.This issue affects GW1500โXS: 1.1.2.1.
2.3
CVE-2024-3220 - Default mimetype known files writeable on Windows
There is a defect in the CPython standard library module โmimetypesโ where on Windows the default list of known file locations are writable meaning other users can create invalid files to cause MemoryError to be raised on Python runtime startup or have file extensions be interpreted as the incorrecโฆ
4.8
CVE-2024-56463 - IBM QRadar SIEM cross-site scripting
IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
6.5
CVE-2024-56477 - IBM Power Hardware Management Console directory traversal
IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.