4.8
CVE-2025-2490 - Dromara ujcms File Upload WebFileUploadController.java upload cross site scripting
A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileUploadController.java of the component File Upload. The manipulation leads to cross site scriptiโฆ
9
CVE-2023-47539 -
An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request.
7.7
CVE-2024-21760 -
An improper control of generation of code ('Code Injection') vulnerability [CWE-94]ย inย FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allowย an authenticated attackerย to execute arbitrary code on the host via a playbook codeโฆ
9.8
CVE-2024-8997 - SQLi in Vestel's EVC04 Configuration Interface
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection.This issue affects EVC04 Configuration Interface: before V3.187, V4.53.
8.8
CVE-2025-2449 - NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability
NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vulnerability in that the target must visit a โฆ
8.8
CVE-2025-2450 - NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability
NI Vision Builder AI VBAI File Processing Missing Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI Vision Builder AI. User interaction is required to exploit this vulnerability in that the target must vโฆ
0.0
CVE-2025-2496 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.3
CVE-2025-2495 - Stored Cross-Site Scripting (XSS) vulnerability in Softdial Contact Center
Stored Cross-Site Scripting (XSS) in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to upload XML files to the server with JavaScript code injected via the โ/softdial/scheduler/save.phpโ resource. The injected code will execute when the uploaded file is loaded via the โโฆ
8.7
CVE-2025-2494 - Unrestricted file upload vulnerability in Softdial Contact Center
Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the โ/softdial/phpconsole/upload.phpโ endpoint, which is protected by basic HTTP authentication. The files are uploaded to a directory exposed by the web apโฆ
6.8
CVE-2025-2489 - Insecure storage of sensitive information in NTFS Tool
Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-tool/config.json.