The data security platform comes with a predictive capability that separates it from other offerings aimed at protecting enterprise data, the startup says.
A vulnerability marked as critical has been reported in Dinstar Monitoring Platform 甘肃省危险品库监控平台 1.0. This impacts an unknown function of the file /itc/$%7BappPath%7D/login_getPasswordErrorNum.action. The manipulation of the argument userBean.loginName leads to sql injection.
This vulnerability is referenced as CVE-2025-8773. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability described as problematic has been identified in riscv-boom SonicBOOM up to 2.2.3. Affected is an unknown function of the component L1 Data Cache Handler. The manipulation results in observable timing discrepancy.
This vulnerability is identified as CVE-2025-8774. The attack is only possible with local access. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical has been found in Qiyuesuo Eelectronic Signature Platform up to 4.34. Affected by this vulnerability is the function execute of the file /api/code/upload of the component Scheduled Task Handler. This manipulation of the argument File causes unrestricted upload.
This vulnerability is tracked as CVE-2025-8775. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical has been found in oitcode samarium up to 0.9.6. The affected element is an unknown function of the file /dashboard/product of the component Create Product Page. The manipulation leads to unrestricted upload.
This vulnerability is referenced as CVE-2025-8798. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability identified as critical has been detected in xujeff tianti 天梯 up to 2.3. Impacted is an unknown function of the file /tianti-module-admin/user/ajax/save. Performing manipulation results in missing authorization.
This vulnerability is known as CVE-2025-8807. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability described as problematic has been identified in Weee RICEPO App 6.17.77 on Android. This impacts an unknown function of the file AndroidManifest.xml of the component com.ricepo.app. Executing manipulation can lead to improper export of android application components.
This vulnerability is registered as CVE-2025-8745. The attack needs to be launched locally. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as problematic has been found in GNU libopts up to 27.6. Affected is the function __strstr_sse2. The manipulation leads to memory corruption. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is documented as CVE-2025-8746. The attack needs to be performed locally. Additionally, an exploit exists.
This issue was initially reported to the tcpreplay project, but the code maintainer explains, that this "bug appears to be in libopts which is an external library."
A vulnerability, which was classified as problematic, was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. This affects an unknown part of the component Block Page. Such manipulation of the argument Category leads to cross site scripting.
This vulnerability is traded as CVE-2025-8751. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562 and classified as critical. This vulnerability affects unknown code of the file /role/add. Performing manipulation results in command injection.
This vulnerability is known as CVE-2025-8752. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
A vulnerability, which was classified as problematic, has been found in Broadcom Symantec PGP Encryption 11.0.1. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-8661. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability, which was classified as problematic, has been found in JasPer up to 4.2.5. The affected element is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 Encoder. This manipulation causes reachable assertion.
The identification of this vulnerability is CVE-2025-8836. The attack can only be executed locally. Furthermore, there is an exploit available.
It is suggested to install a patch to address this issue.
A vulnerability, which was classified as critical, was found in JasPer up to 4.2.5. The impacted element is the function jpc_dec_dump of the file src/libjasper/jpc/jpc_dec.c of the component JPEG2000 File Handler. Such manipulation leads to use after free.
This vulnerability is referenced as CVE-2025-8837. The attack can only be performed from a local environment. Furthermore, an exploit is available.
A patch should be applied to remediate this issue.
A vulnerability classified as problematic was found in JasPer up to 4.2.5. Impacted is the function jas_image_chclrspc of the file src/libjasper/base/jas_image.c of the component Image Color Space Conversion Handler. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-8835. The attack needs to be approached locally. In addition, an exploit is available.
Applying a patch is advised to resolve this issue.
A vulnerability classified as problematic was found in Broadcom Symantec PGP Encryption 11.0.1. Affected by this vulnerability is an unknown functionality. Executing manipulation can lead to improper privilege management.
This vulnerability is handled as CVE-2025-8660. The attack can be executed remotely. There is not any exploit available.
A vulnerability has been found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e and classified as critical. This affects an unknown part of the file /index of the component Shiro Configuration. The manipulation leads to path traversal.
This vulnerability is listed as CVE-2025-8815. The attack may be initiated remotely. In addition, an exploit is available.
This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available.
A vulnerability labeled as critical has been found in MigoXLab LMeterX 1.2.0. This issue affects the function process_cert_files of the file backend/service/upload_service.py. The manipulation of the argument task_id results in path traversal.
This vulnerability is cataloged as CVE-2025-8729. The attack may be launched remotely. Furthermore, there is an exploit available.
Applying a patch is advised to resolve this issue.
A vulnerability was found in Portabilis i-Educar up to 2.10. It has been declared as problematic. This issue affects some unknown processing of the file /intranet/educar_calendario_dia_motivo_cad.php of the component Calendar Module. The manipulation of the argument Motivo/descricao results in cross site scripting.
This vulnerability is known as CVE-2025-7868. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
Microsoft found that the group behind RaccoonO365 has been paid at least $100,000 in cryptocurrency from about 100 subscriptions. This is likely only a portion of the money earned from the tool, according to Microsoft.
A vulnerability identified as critical has been detected in Zimbra Collaboration Suite. This affects an unknown function of the component EnableTwoFactorAuthRequest SOAP Endpoint. Performing manipulation results in improper authentication.
This vulnerability is known as CVE-2025-54391. Remote exploitation of the attack is possible. No exploit is available.