A vulnerability was found in Tenda AC9 15.03.05.19. It has been rated as problematic. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials.
This vulnerability is handled as CVE-2025-9731. It is possible to launch the attack on the local host. Additionally, an exploit exists.
A vulnerability was found in O2OA up to 10.0-410 and classified as problematic. The impacted element is an unknown function of the file /x_query_assemble_designer/jaxrs/stat of the component Personal Profile Page. The manipulation of the argument name/alias/description/applicationName results in cross site scripting.
This vulnerability is reported as CVE-2025-9734. The attack can be launched remotely. Moreover, an exploit is present.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability was found in O2OA up to 10.0-410. It has been classified as problematic. This affects an unknown function of the file /x_query_assemble_designer/jaxrs/table of the component Personal Profile Page. This manipulation of the argument description/applicationName/queryName causes cross site scripting.
This vulnerability appears as CVE-2025-9735. The attack may be initiated remotely. In addition, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability was found in O2OA up to 10.0-410. It has been declared as problematic. This impacts an unknown function of the file /x_query_assemble_designer/jaxrs/statement of the component Personal Profile Page. Such manipulation of the argument description/queryName leads to cross site scripting.
This vulnerability is traded as CVE-2025-9736. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
A vulnerability, which was classified as critical, was found in Apple iOS and iPadOS. Affected by this issue is some unknown functionality of the component Shortcut Handler. The manipulation results in improper access controls.
This vulnerability was named CVE-2024-44269. The attack needs to be approached locally. There is no available exploit.
You should upgrade the affected component.
A vulnerability classified as critical was found in Apple macOS. Affected is an unknown function of the component Shortcut Handler. Executing manipulation can lead to improper access controls.
This vulnerability is handled as CVE-2024-44269. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in Apple visionOS. Affected by this vulnerability is an unknown functionality of the component Shortcut Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2024-44269. Local access is required to approach this attack. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in Apple macOS up to 13.6/14.6. This issue affects some unknown processing. Performing manipulation results in improper access controls.
This vulnerability is known as CVE-2024-44267. Attacking locally is a requirement. No exploit is available.
You should upgrade the affected component.
A vulnerability identified as problematic has been detected in Apple iOS and iPadOS. The affected element is an unknown function. Performing manipulation results in state issue.
This vulnerability was named CVE-2024-44259. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.