The Progress Telerik Report Server 2024 Q1 version 10.0.24.305 and earlier allows attackers to bypass authentication. This vulnerability has been assigned CVE-2024-4358.
The exploit allows an attacker to execute remote code in FoxCMS v.1.2.5. By sending a specially crafted payload to the target, an attacker can run arbitrary commands on the system. This vulnerability is identified as CVE-2025-29306.
The Rejetto HTTP File Server version 2.3m is vulnerable to remote code execution, allowing attackers to execute arbitrary code on the server. This vulnerability has been assigned the CVE-2024-23692.
Langflow version < 1.3.0 is vulnerable to remote code execution (RCE) due to a lack of proper input validation. An attacker can exploit this by sending crafted HTTP requests, leading to the execution of arbitrary code on the target system. This vulnerability has been assigned CVE-2025-3248.
The Sonatype Nexus Repository 3.53.0-01 is vulnerable to a path traversal exploit, allowing an attacker to access files and directories outside of the web root directory. This vulnerability has been assigned CVE-2024-4956.