| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Unauthenticated Local File Inclusion in Right Way <= 4.0 versions. |
| Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions. |
| Unauthenticated Local File Inclusion in EcoBlue <= 1.15 versions. |
| Unauthenticated Local File Inclusion in Malmö <= 2.2 versions. |
| Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions. |
| Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions. |
| Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions. |
| Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions. |
| Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions. |
| Unauthenticated Local File Inclusion in Gamic <= 1.15 versions. |
| Unauthenticated Local File Inclusion in Granola <= 1.13 versions. |
| Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions. |
| Unauthenticated Local File Inclusion in Etude <= 1.6 versions. |
| Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions. |
| Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. |
| Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. |
| NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cloud metadata endpoints, enabling internal network scanning and sensitive data exfiltration. |
| An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exported Content Provider URI. |
| Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.19 and below, a single crafted deep link can silently hijack all GPS tracking parameters and redirect telemetry to an attacker-controlled server. The app registers a custom org.traccar.client://config deep-link scheme that silently writes attacker-supplied parameters (server URL, device ID, accuracy, distance, and interval) into the app's persistent configuration with no confirmation, notification, or visual indication. A single crafted link delivered via SMS, email, a webpage, or any installed app can therefore reconfigure the app the moment the victim taps it, with no special permissions required. As a result, an attacker can covertly redirect all of the victim's GPS telemetry to their own server at maximum precision and frequency, and the change persists across restarts. This gives the attacker continuous, real-time tracking of the victim's location. This issue has been fixed in version 9.7.20. |
| Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions. |