5.3
CVE-2025-1969 - Request approval spoofing in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
Improper request input validation in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center allows a user to modify a valid request and spoof an approval in TEAM. Upgrade TEAM to the latest release v.1.2.2. Follow instructions in updating TEAM documentation for updating process
5.3
CVE-2025-1947 - hzmanyun Education and Training System UploadImageController.java scorm command injection
A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the function scorm of the file UploadImageController.java. The manipulation of the argument param leads to command injection. It is possible to initiate the attack remotely. The exploβ¦
5.3
CVE-2025-1946 - hzmanyun Education and Training System exportPDF command injection
A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this issue is the function exportPDF of the file /user/exportPDF. The manipulation of the argument id leads to command injection. The attack may be launched remotely. The exploit has β¦
5.3
CVE-2020-3122 - Cisco Content Security Management Appliance Information Disclosure Vulnerability
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to obtain sensitive network information.
7.5
CVE-2019-1815 - Cisco Meraki MX67 and MX68 Sensitive Information Disclosure Vulnerability
A security vulnerability was discovered in the local status page functionality of Cisco Merakiβs MX67 and MX68 security appliance models that may allow unauthenticated individuals to access and download logs containing sensitive, privileged device information. The vulnerability is due to improper aβ¦
7.1
CVE-2024-10930 - Carrier Block Load Privilege Escalation
An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.
7.7
CVE-2024-41147 -
An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
4.6
CVE-2025-27402 - Tuleap is missing CSRF protections on tracker fields administrative operations
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap is missing CSRF protections on tracker fields administrative operations. An attacker could use this vulnerability to trick victims into removing or updating tracker fields. This vulnerability is β¦
4.6
CVE-2025-27401 - In Tuleap, deleting a report can delete criteria filters in other reports
Tuleap is an Open Source Suite to improve management of software developments and collaboration. In a standard usages of Tuleap, the issue has a limited impact, it will mostly leave dangling data. However, a malicious user could create and delete reports multiple times to cycle through all the filtβ¦
4.1
CVE-2025-27156 - Tuleap allows content injection via emails sent by the mass emailing features
Tuleap is an Open Source Suite to improve management of software developments and collaboration. The mass emailing features do not sanitize the content of the HTML emails. A malicious user could use this issue to facilitate a phishing attempt or to indirectly exploit issues in the recipients mail cβ¦