Vulnerabilities

  

CVE-2025-65826 | Meatmeet App on Android improper authorization

A vulnerability has been found in Meatmeet App on Android and classified as critical. Impacted is an unknown function. Performing

  

CVE-2020-36886 | SpenetiX Fusion Digital Signage up to 8.2.26 cross-site request forgery (Exploit 48846 / EDB-48846)

A vulnerability was found in SpenetiX Fusion Digital Signage up to 8.2.26 and classified as problematic. The affected element is

  

CVE-2020-36900 | All-Dynamics Digital Signage System 2.0.2 cross-site request forgery (Exploit 48736 / EDB-48736)

A vulnerability was found in All-Dynamics Digital Signage System 2.0.2. It has been classified as problematic. The impacted element is

  

CVE-2025-67646 | Telepedia TableProgressTracking up to 1.2.0 REST API cross-site request forgery (GHSA-j24f-hw6w-cq78)

A vulnerability was found in Telepedia TableProgressTracking up to 1.2.0. It has been declared as problematic. This affects an unknown

  

CVE-2025-67513 | FreePBX up to 16.0.95/17.0.9 app_password weak password (GHSA-426v-c5p7-cp29)

A vulnerability was found in FreePBX up to 16.0.95/17.0.9. It has been rated as critical. This impacts an unknown function.

  

CVE-2020-36884 | BrightSign Digital Signage Diagnostic Web Server up to 8.2.26 Speed Test Service url server-side request forgery (Exploit 48843 / EDB-48843)

A vulnerability categorized as critical has been discovered in BrightSign Digital Signage Diagnostic Web Server up to 8.2.26. Affected is

  

CVE-2020-36901 | UBICOD Medivision Digital Signage 1.5.1 /query/user/itSet cross-site request forgery (Exploit 48694 / EDB-48694)

A vulnerability identified as problematic has been detected in UBICOD Medivision Digital Signage 1.5.1. Affected by this vulnerability is an

  

CVE-2025-65825 | Meatmeet App on Android cleartext storage

A vulnerability labeled as problematic has been found in Meatmeet App on Android. Affected by this issue is some unknown

  

CVE-2024-58285 | Chyrp 2.5.2 Session Cookie Title cross site scripting (Exploit 52013 / EDB-52013)

A vulnerability marked as problematic has been reported in Chyrp 2.5.2. This affects an unknown part of the component Session

  

CVE-2025-65829 | Meatmeet App on Android Secure Boot Feature improper authentication

A vulnerability described as critical has been identified in Meatmeet App on Android. This vulnerability affects unknown code of the

  

CVE-2025-65832 | Meatmeet App on Android sensitive information in memory

A vulnerability classified as critical has been found in Meatmeet App on Android. This issue affects some unknown processing. This

  

CVE-2025-65822 | Meatmeet App on Android Wi-Fi Network improper authorization

A vulnerability classified as critical was found in Meatmeet App on Android. Impacted is an unknown function of the component

  

CVE-2025-66472 | xwiki xwiki-platform up to 16.10.9/17.4.1 Confirmation Message cross site scripting (GHSA-7vpr-jm38-wr7w)

A vulnerability, which was classified as problematic, has been found in xwiki xwiki-platform up to 16.10.9/17.4.1. The affected element is

  

CVE-2025-14498 | TradingView Desktop Electron uncontrolled search path (ZDI-25-1070)

A vulnerability, which was classified as problematic, was found in TradingView Desktop. The impacted element is an unknown function of

  

CVE-2025-14499 | IceWarp gmaps cross site scripting (ZDI-25-1071)

A vulnerability has been found in IceWarp and classified as problematic. This affects an unknown function of the component gmaps.

  

CVE-2025-14500 | IceWarp X-File-Operation command injection (ZDI-25-1072)

A vulnerability was found in IceWarp and classified as critical. This impacts an unknown function of the component X-File-Operation Handler.

  

CVE-2025-14514 | Campcodes Supplier Management System 1.0 add_distributor.php txtDistributorAddress sql injection

A vulnerability was found in Campcodes Supplier Management System 1.0. It has been classified as critical. Affected is an unknown

  

CVE-2025-14515 | Campcodes Supplier Management System 1.0 /admin/add_unit.php txtunitDetails sql injection

A vulnerability was found in Campcodes Supplier Management System 1.0. It has been declared as critical. Affected by this vulnerability

  

CVE-2025-14516 | Yalantis uCrop 2.2.11 URL com.yalantis.ucrop.task.BitmapLoadTask.java downloadFile server-side request forgery

A vulnerability was found in Yalantis uCrop 2.2.11. It has been rated as critical. Affected by this issue is the

  

CVE-2025-14517 | Yalantis uCrop 2.2.11 AndroidManifest.xml UCropActivity  improper export of android application components

A vulnerability categorized as problematic has been discovered in Yalantis uCrop 2.2.11. This affects the function UCropActivity  of the file

  

CVE-2025-14518 | PoweJob up to 5.1.2 Network Request PingPongUtils.java checkConnectivity targetIp/targetPort server-side request forgery (Issue 1144)

A vulnerability identified as critical has been detected in PoweJob up to 5.1.2. This vulnerability affects the function checkConnectivity of

  

CVE-2025-14519 | baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c advtext add cross site scripting

A vulnerability labeled as problematic has been found in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. This issue affects some unknown processing

  

CVE-2025-14520 | baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c delfile filename path traversal

A vulnerability marked as critical has been reported in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown function of

  

CVE-2025-14521 | baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c download filename path traversal

A vulnerability described as critical has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The affected element is an unknown

  

CVE-2025-14522 | baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c upload_json.php imgFile unrestricted upload

A vulnerability classified as critical has been found in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown

  

CVE-2025-67738 | Webmin up to 2.599 Squid squid/cachemgr.cgi os command injection

A vulnerability classified as critical was found in Webmin up to 2.599. This affects an unknown function of the file

  

CVE-2020-36885 | Sony IPELA Network Camera up to 1.82.01 HTTP POST Request ftpclient.cgi out-of-bounds write (Exploit 48842 / EDB-48842)

A vulnerability was found in Sony IPELA Network Camera up to 1.82.01. It has been classified as critical. The affected

  

CVE-2023-53776 | DB Elettronica Telecomunicazioni Screen SFT DAB 1.9.3 Device Management API session fixiation (Exploit 51459 / EDB-51459)

A vulnerability was found in DB Elettronica Telecomunicazioni Screen SFT DAB 1.9.3. It has been declared as critical. The impacted

  

CVE-2025-67717 | Zitadel up to 3.4.4/4.7.1 totalResult exposure of sensitive system information to an unauthorized control sphere (GHSA-f4cf-9rvr-2rcx)

A vulnerability was found in Zitadel up to 3.4.4/4.7.1. It has been rated as problematic. This affects an unknown function.

  

CVE-2025-66473 | xwiki xwiki-platform up to 16.10.10/17.4.3/17.6.x REST API /rest/wikis/xwiki/spaces allocation of resources (GHSA-cc84-q3v3-mhgf)

A vulnerability categorized as problematic has been discovered in xwiki xwiki-platform up to 16.10.10/17.4.3/17.6.x. This impacts an unknown function of

  

CVE-2020-36887 | SpinetiX Fusion Digital Signage up to 3.4.8 Database Backup /content/files/backups/ cleartext storage (Exploit 48845 / EDB-48845)

A vulnerability identified as problematic has been detected in SpinetiX Fusion Digital Signage up to 3.4.8. Affected is an unknown

  

CVE-2025-65292 | Aqara Camera Hub G3/Hub M2/Hub M3 Domain Name command injection

A vulnerability labeled as critical has been found in Aqara Camera Hub G3, Hub M2 and Hub M3. Affected by

  

CVE-2025-65293 | Aqara Camera Hub G3 up to 4.1.9 QR Code command injection

A vulnerability marked as critical has been reported in Aqara Camera Hub G3 up to 4.1.9. Affected by this issue

  

CVE-2025-67713 | miniflux up to 2.2.14 Relative URL IsAbs redirect (GHSA-wqv2-4wpg-8hc9)

A vulnerability described as problematic has been identified in miniflux up to 2.2.14. This affects the function IsAbs of the

  

CVE-2025-65294 | Aqara Camera Hub G3/Hub M2/Hub M3 privilege escalation

A vulnerability classified as critical has been found in Aqara Camera Hub G3, Hub M2 and Hub M3. This vulnerability

  

CVE-2025-67644 | langchain-ai langgraph up to 3.0.0 CheckpointSaver _metadata_predicate sql injection (GHSA-9rwj-6rc7-p77c)

A vulnerability classified as critical was found in langchain-ai langgraph up to 3.0.0. This issue affects the function _metadata_predicate of

  

CVE-2025-67511 | aliasrobotics cai up to 0.5.9 run_ssh_command_with_credentials port command injection (GHSA-4c65-9gqf-4w8h)

A vulnerability, which was classified as critical, has been found in aliasrobotics cai up to 0.5.9. Impacted is the function

  

CVE-2025-11247 | GitLab Enterprise Edition up to 18.4.5/18.5.3/18.6.1 GraphQL authorization (Issue 573766)

A vulnerability, which was classified as problematic, was found in GitLab Enterprise Edition up to 18.4.5/18.5.3/18.6.1. The affected element is

  

CVE-2025-12562 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 GraphQL allocation of resources (Issue 579152)

A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1 and classified as critical. The

  

CVE-2025-13978 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 Private Project information exposure (ID 566960)

A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1 and classified as problematic. This affects

  

CVE-2025-66628 | ImageMagick up to 7.1.2-9/7.1.2-10 TIM Image Parser coders/tim.c width/height out-of-bounds (GHSA-6hjr-v6g4-3fm8)

A vulnerability was found in ImageMagick up to 7.1.2-9/7.1.2-10. It has been classified as problematic. This impacts an unknown function

  

CVE-2025-65297 | Aqara Camera Hub G3/Hub M2/Hub M3 cleartext transmission

A vulnerability was found in Aqara Camera Hub G3, Hub M2 and Hub M3. It has been declared as problematic.

  

CVE-2025-65295 | Aqara Camera Hub G3/Hub M2/Hub M3 Firmware Update code download

A vulnerability was found in Aqara Camera Hub G3, Hub M2 and Hub M3. It has been rated as problematic.

  

CVE-2020-36892 | EIBIZ i-Media Server Digital Signage up to 3.8.0 Setting /messagebroker/amf updateUser missing authentication (Exploit 48774 / EDB-48774)

A vulnerability categorized as critical has been discovered in EIBIZ i-Media Server Digital Signage up to 3.8.0. Affected by this

  

CVE-2020-36894 | EIBIZ i-Media Server Digital Signage up to 3.8.0 AMF /messagebroker/amf missing authentication (Exploit 48763 / EDB-48763)

A vulnerability identified as critical has been detected in EIBIZ i-Media Server Digital Signage up to 3.8.0. This affects an

  

CVE-2020-36896 | Qihang Media Web Digital Signage 3.0.9 XML File Parser /xml/User/User.xml insufficiently protected credentials (Exploit 48748 / EDB-48748)

A vulnerability labeled as problematic has been found in Qihang Media Web Digital Signage 3.0.9. This vulnerability affects unknown code

  

CVE-2023-53775 | DB Elettronica Telecomunicazioni Screen SFT DAB 1.9.3 userManager API session fixiation (Exploit 51456 / EDB-51456)

A vulnerability marked as critical has been reported in DB Elettronica Telecomunicazioni Screen SFT DAB 1.9.3. This issue affects some

  

CVE-2025-67719 | ibexa user up to 5.0.3 unverified password change (GHSA-x93p-w2ch-fg67)

A vulnerability described as problematic has been identified in ibexa user up to 5.0.3. Impacted is an unknown function. The

  

CVE-2025-67720 | Mayuri-Chan pyrofork up to 2.3.68 Telegram Message path traversal (GHSA-6h2f-wjhf-4wjx)

A vulnerability classified as critical has been found in Mayuri-Chan pyrofork up to 2.3.68. The affected element is an unknown

  

CVE-2025-67718 | formio Form.io up to 3.5.6/4.4.2 on Serverless API Endpoint case sensitivity (GHSA-m654-769v-qjv7)

A vulnerability classified as problematic was found in formio Form.io up to 3.5.6/4.4.2 on Serverless. The impacted element is an

  

CVE-2025-67716 | auth0 nextjs-auth0 up to 4.12.x returnTo incomplete blacklist (GHSA-mr6f-h57v-rpj5)

A vulnerability, which was classified as critical, has been found in auth0 nextjs-auth0 up to 4.12.x. This affects an unknown

  

CVE-2025-11984 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 WebAuthn Two-Factor Authentication authentication bypass (Issue 577847)

A vulnerability, which was classified as critical, was found in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1. This

  

CVE-2025-4097 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 allocation of resources (Issue 538192)

A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1 and classified as critical. Affected

  

CVE-2020-36897 | Qihang QiHang Media Web Digital Signage 3.0.9 QH.aspx remotePath/fileToUpload unrestricted upload (Exploit 48751 / EDB-48751)

A vulnerability was found in Qihang QiHang Media Web Digital Signage 3.0.9 and classified as critical. Affected by this vulnerability

  

CVE-2020-36899 | Qihang QiHang Media Web Digital Signage 3.0.9.0 QH.aspx path/filename backup (Exploit 48750 / EDB-48750)

A vulnerability was found in Qihang QiHang Media Web Digital Signage 3.0.9.0. It has been classified as problematic. Affected by

  

CVE-2025-65290 | Aqara Camera Hub G3/Hub M2/Hub M3 Firmware Update certificate validation

A vulnerability was found in Aqara Camera Hub G3, Hub M2 and Hub M3. It has been declared as critical.

  

CVE-2025-65291 | Aqara Camera Hub G3/Hub M2/Hub M3 certificate validation

A vulnerability was found in Aqara Camera Hub G3, Hub M2 and Hub M3. It has been rated as critical.

  

CVE-2020-36898 | Qihang Media Web Digital Signage 3.0.9 QH.aspx data path traversal (Exploit 48749 / EDB-48749)

A vulnerability categorized as critical has been discovered in Qihang Media Web Digital Signage 3.0.9. This issue affects some unknown

  

CVE-2025-8405 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 cross site scripting (Issue 558214)

A vulnerability identified as problematic has been detected in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1. Impacted is

  

CVE-2025-12716 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 cross site scripting (Issue 579548)

A vulnerability labeled as problematic has been found in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1. The affected

  

CVE-2025-14157 | GitLab Community Edition/Enterprise Edition up to 18.4.5/18.5.3/18.6.1 API allocation of resources (Issue 574324)

A vulnerability marked as critical has been reported in GitLab Community Edition and Enterprise Edition up to 18.4.5/18.5.3/18.6.1. The impacted

  

CVE-2025-67490 | auth0 nextjs-auth0 up to 4.11.1/4.12.0 TokenRequestCache authorization (GHSA-wcgj-f865-c7j7)

A vulnerability described as problematic has been identified in auth0 nextjs-auth0 up to 4.11.1/4.12.0. This affects the function TokenRequestCache. Such

  

CVE-2025-67505 | okta okta-sdk-java up to 20.0.0 Okta Management API ApiClient race condition (GHSA-j5gq-897m-2rff)

A vulnerability classified as problematic has been found in okta okta-sdk-java up to 20.0.0. This impacts the function ApiClient of

  

CVE-2025-65296 | Aqara Camera Hub G3/Hub M2/Hub M3 JSON null pointer dereference

A vulnerability classified as problematic was found in Aqara Camera Hub G3, Hub M2 and Hub M3. Affected is an

  

CVE-2025-66033 | okta okta-sdk-java up to 24.0.0 Okta Management API memory leak (GHSA-qhr6-6cgv-6638)

A vulnerability, which was classified as problematic, has been found in okta okta-sdk-java up to 24.0.0. Affected by this vulnerability

  

CVE-2020-36902 | UBICOD Medivision Digital Signage 1.5.1 /html/user ft[grp] authorization (Exploit 48684 / EDB-48684)

A vulnerability, which was classified as very critical, was found in UBICOD Medivision Digital Signage 1.5.1. Affected by this issue

  

CVE-2023-53740 | DB Elettronica Telecomunicazioni Screen SFT DAB 1.9.3 JSON userManager.cgx authorization (Exploit 51458 / EDB-51458)

A vulnerability has been found in DB Elettronica Telecomunicazioni Screen SFT DAB 1.9.3 and classified as problematic. This affects an

  

CVE-2025-65512 | markdownify-mcp up to 0.0.2 server-side request forgery

A vulnerability was found in markdownify-mcp up to 0.0.2 and classified as critical. This vulnerability affects unknown code. Such manipulation

  

CVE-2025-65950 | WBCE CMS up to 1.6.4 User Management admin/users/save.php groups[] sql injection (GHSA-934v-xhx9-j2f3)

A vulnerability was found in WBCE CMS up to 1.6.4. It has been classified as critical. This issue affects some

  

CVE-2025-65824 | Meatmeet App on Android Bluetooth Low Energy improper authentication

A vulnerability was found in Meatmeet App on Android. It has been declared as critical. Impacted is an unknown function

  

CVE-2023-53741 | DB Elettronica Telecomunicazioni Screen SFT DAB 1.9.3 API session fixiation (Exploit 51457 / EDB-51457)

A vulnerability was found in DB Elettronica Telecomunicazioni Screen SFT DAB 1.9.3. It has been rated as critical. The affected

  

CVE-2025-65830 | Meatmeet App on Android certificate validation

A vulnerability categorized as critical has been discovered in Meatmeet App on Android. The impacted element is an unknown function.

  

CVE-2025-62181 | Pegasystems Pega Infinity up to 25.1.0 Authentication Service observable response discrepancy

A vulnerability identified as problematic has been detected in Pegasystems Pega Infinity up to 25.1.0. This affects an unknown function

  

CVE-2025-65820 | Meatmeet App up to 1.1.2.0 on Android access control

A vulnerability labeled as critical has been found in Meatmeet App up to 1.1.2.0 on Android. This impacts an unknown

  

CVE-2025-65827 | Meatmeet App on Android API cleartext transmission

A vulnerability marked as problematic has been reported in Meatmeet App on Android. Affected is an unknown function of the

  

CVE-2025-65828 | Meatmeet on Android Bluetooth Low Energy denial of service

A vulnerability described as problematic has been identified in Meatmeet on Android. Affected by this vulnerability is an unknown functionality

openSUSE 15 SP6: python-Django Important Denial of Service Fix 2025:0465-1
  

openSUSE 15 SP6: python-Django Important Denial of Service Fix 2025:0465-1

An update that fixes two vulnerabilities is now available.LinuxSecurity – Security AdvisoriesRead More

Debian: firefox-esr Critical Privilege Escalation DSA-6078-1 CVE-2025-14321
  

Debian: firefox-esr Critical Privilege Escalation DSA-6078-1 CVE-2025-14321

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of

Ubuntu 25.10: Linux Kernel Critical Update System Threat CVE-2025-40018
  

Ubuntu 25.10: Linux Kernel Critical Update System Threat CVE-2025-40018

Several security issues were fixed in the Linux kernel.LinuxSecurity – Security AdvisoriesRead More

Debian: Important DoS Vulnerabilities in FFmpeg DSA-6080-1 Advisory
  

Debian: Important DoS Vulnerabilities in FFmpeg DSA-6080-1 Advisory

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the

Ubuntu 20.04 LTS: USN-7922-1 Linux Kernel Important Security Issues
  

Ubuntu 20.04 LTS: USN-7922-1 Linux Kernel Important Security Issues

Several security issues were fixed in the Linux kernel.LinuxSecurity – Security AdvisoriesRead More

Ubuntu 24.04 LTS: Kernel Important Security Fixes USN-7921-1 CVE-2025-39946
  

Ubuntu 24.04 LTS: Kernel Important Security Fixes USN-7921-1 CVE-2025-39946

Several security issues were fixed in the Linux kernel.LinuxSecurity – Security AdvisoriesRead More

  

CVE-2025-64626 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability described as problematic has been identified in Adobe Experience Manager up to 6.5.23. This impacts an unknown function.

  

CVE-2025-64627 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability classified as problematic has been found in Adobe Experience Manager up to 6.5.23. Affected is an unknown function.

  

CVE-2025-64789 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability classified as problematic was found in Adobe Experience Manager up to 6.5.23. Affected by this vulnerability is an

  

CVE-2025-64790 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability, which was classified as problematic, has been found in Adobe Experience Manager up to 6.5.23. Affected by this

  

CVE-2025-64792 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability, which was classified as problematic, was found in Adobe Experience Manager up to 6.5.23. This affects an unknown

  

CVE-2025-64793 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability has been found in Adobe Experience Manager up to 6.5.23 and classified as problematic. This vulnerability affects unknown

  

CVE-2025-64796 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability was found in Adobe Experience Manager up to 6.5.23 and classified as problematic. This issue affects some unknown

  

CVE-2025-64791 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability was found in Adobe Experience Manager up to 6.5.23. It has been classified as problematic. Impacted is an

  

CVE-2025-64794 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability was found in Adobe Experience Manager up to 6.5.23. It has been declared as problematic. The affected element

  

CVE-2025-64803 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability was found in Adobe Experience Manager up to 6.5.23. It has been rated as problematic. The impacted element

  

CVE-2025-64801 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability categorized as problematic has been discovered in Adobe Experience Manager up to 6.5.23. This affects an unknown function.

  

CVE-2025-64802 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability identified as problematic has been detected in Adobe Experience Manager up to 6.5.23. This impacts an unknown function.

  

CVE-2025-64808 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability labeled as problematic has been found in Adobe Experience Manager up to 6.5.23. Affected is an unknown function.

  

CVE-2025-64800 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability marked as problematic has been reported in Adobe Experience Manager up to 6.5.23. Affected by this vulnerability is

  

CVE-2025-64804 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability described as problematic has been identified in Adobe Experience Manager up to 6.5.23. Affected by this issue is

  

CVE-2025-64799 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability classified as problematic has been found in Adobe Experience Manager up to 6.5.23. This affects an unknown part.

  

CVE-2025-64814 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability classified as problematic was found in Adobe Experience Manager up to 6.5.23. This vulnerability affects unknown code. Executing

  

CVE-2025-64797 | Adobe Experience Manager up to 6.5.23 cross site scripting (apsb25-115)

A vulnerability, which was classified as problematic, has been found in Adobe Experience Manager up to 6.5.23. This issue affects