5.3
CVE-2025-8123 - deerwms deer-wms-2 edit sql injection
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclos…
7.1
CVE-2025-31952 - HCL iAutomate is affected by an insufficient session expiration
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
7.6
CVE-2025-31955 - HCL iAutomate is affected by a sensitive data exposure vulnerability
HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system.
9.3
CVE-2025-6260 - Network Thermostat X-Series WiFi Thermostats Missing Authentication for Critical Function
The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local area network or from the Internet via a router with port forwarding set up, to gain direct access to the thermostat's embedded web server and reset user…
5.9
CVE-2025-7404 - Calibre Web 0.6.24 & Autocaliweb 0.7.0 - Blind C
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
7.1
CVE-2025-31953 - HCL iAutomate is affected by hardcoded credentials
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
8.7
CVE-2025-6998 - Calibre Web 0.6.24 & Autocaliweb 0.7.0 - ReDoS
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nico…
5.1
CVE-2025-8115 - PHPGurukul Taxi Stand Management System new-autoortaxi-entry-form.php cross site scripting
A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/new-autoortaxi-entry-form.php. The manipulation of the argument registrationnumber/licensenumber leads to cross …
7.8
CVE-2025-5039 - Privilege Ecalation due to Untrusted Search Path Vulnerability
A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in the context of the current process due to an untrusted search path being utilized.
5.4
CVE-2025-46993 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…