Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2025-05-28 CVE-2025-46777 Information Exposure Through Log Files vulnerability in Fortinet Fortiportal
A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin permissions to view encrypted secrets via the FortiPortal System Log.
network
low complexity
fortinet CWE-532
2.7
2025-05-28 CVE-2025-47295 Buffer Over-read vulnerability in Fortinet Fortios
A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare conditions that are outside of the attacker's control.
network
high complexity
fortinet CWE-126
3.7
2025-05-26 CVE-2025-5179 Code Injection vulnerability in Realcetecnologia Queue Ticket Kiosk
A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517.
network
low complexity
realcetecnologia CWE-94
3.4
2025-05-25 CVE-2025-5138 A vulnerability was found in Bitwarden up to 2.25.1.
network
low complexity
CWE-94
3.5
2025-05-21 CVE-2025-5031 A vulnerability was found in Ackites KillWxapkg up to 2.4.1.
network
high complexity
CWE-400
3.1
2025-05-20 CVE-2025-5007 A vulnerability was found in Part-DB up to 1.17.0.
network
low complexity
CWE-94
3.5
2025-05-20 CVE-2025-4996 A vulnerability, which was classified as problematic, has been found in Intelbras RF 301K 1.1.5.
network
low complexity
CWE-94
2.4
2025-05-18 CVE-2025-4852 Cross-site Scripting vulnerability in Totolink A3002R Firmware 2.1.1B20230720.1011
A vulnerability, which was classified as problematic, has been found in TOTOLINK A3002R 2.1.1-B20230720.1011.
network
low complexity
totolink CWE-79
3.4
2025-05-17 CVE-2025-4819 A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0.
network
high complexity
CWE-266
3.1
2025-05-13 CVE-2025-30012 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM stack to accept binary Java objects in specific encoding format.
high complexity
CWE-502
3.9