5.3
CVE-2025-0584 - aEnrich Technology a+HRD - Server-Side Request Forgery (SSRF)
The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.
2
CVE-2024-13524 - obsproject OBS Studio untrusted search path
A vulnerability has been found in obsproject OBS Studio up to 30.0.2 on Windows and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to untrusted search path. The attack needs to be approached locally. The complexity of an attack is ratheβ¦
6.1
CVE-2025-0583 - aEnrich Technology a+HRD - Reflected Cross-site Scripting(XSS)
The a+HRD from aEnrich Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
5.3
CVE-2025-0578 - Facile Sistemas Cloud Apps Password Reset forgotpassword cross site scripting
A vulnerability was found in Facile Sistemas Cloud Apps up to 20250107. It has been classified as problematic. Affected is an unknown function of the file /account/forgotpassword of the component Password Reset Handler. The manipulation of the argument reterros leads to cross site scripting. It is β¦
5.5
CVE-2023-52923 - netfilter: nf_tables: adapt set backend to use GC transaction API
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: adapt set backend to use GC transaction API Use the GC transaction API to replace the old and buggy gc API and the busy mark approach. No set elements are removed from async garbage collection anymore, instβ¦
8.4
CVE-2025-24337 -
WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
4.7
CVE-2025-21655 - io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period
In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but when dropping the reference to the io_ev_fd, it calls io_eventfd_free() directly if the refcount dβ¦
5.4
CVE-2025-0604 - Keycloak-ldap-federation: authentication bypass due to missing ldap bind after password reset in keβ¦
A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expired or disabled to regain access in Keycloak, bypassing AD rβ¦
8.6
CVE-2024-11218 - Podman: buildah: container breakout by using --jobs=2 and a race condition when building a maliciouβ¦
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the hβ¦
6.9
CVE-2025-0576 - Mobotix M15 player cross site scripting
A vulnerability was found in Mobotix M15 4.3.4.83 and classified as problematic. This issue affects some unknown processing of the file /control/player?center&eventlist&pda&dummy_for_reload=1736177631&p_evt. The manipulation of the argument p_qual leads to cross site scripting. The attack may be inβ¦