Vulnerabilities (CVE)

Total 400512 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-58584 1 Sick 5 Baggage Analytics, Enterprise Analytics, Logistic Diagnostic Analytics and 2 more 2026-06-17 N/A 5.3 MEDIUM
In the HTTP request, the username and password are transferred directly in the URL as parameters. However, URLs can be stored in various systems such as server logs, browser histories or proxy servers. As a result, there is a high risk that this sensitive data will be disclosed unintentionally.
CVE-2025-58583 1 Sick 1 Enterprise Analytics 2026-06-17 N/A 5.3 MEDIUM
The application provides access to a login protected H2 database for caching purposes. The username is prefilled.
CVE-2025-58582 1 Sick 1 Enterprise Analytics 2026-06-17 N/A 5.3 MEDIUM
If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.
CVE-2025-58581 1 Sick 1 Enterprise Analytics 2026-06-17 N/A 4.3 MEDIUM
When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other internal information. An attacker can thus obtain information about the technology used and the structure of the application.
CVE-2025-58580 1 Sick 1 Enterprise Analytics 2026-06-17 N/A 6.5 MEDIUM
An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log entries and thus falsify or dilute logs, for example.
CVE-2025-58579 1 Sick 5 Baggage Analytics, Enterprise Analytics, Logistic Diagnostic Analytics and 2 more 2026-06-17 N/A 5.3 MEDIUM
Due to a lack of authentication, it is possible for an unauthenticated user to request data from this endpoint, making the application vulnerable for user enumeration.
CVE-2025-58578 1 Sick 1 Enterprise Analytics 2026-06-17 N/A 3.8 LOW
A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no quotas, checking mechanisms or restrictions to limit the creation.
CVE-2025-58576 1 Groupsession 1 Groupsession 2026-06-17 N/A 4.3 MEDIUM
Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5.3.2. If a user accesses a malicious page while logged in, unintended operations may be performed.
CVE-2025-58487 1 Samsung 1 Account 2026-06-17 N/A 4.0 MEDIUM
Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.
CVE-2025-58482 1 Samsung 1 Motionphoto 2026-06-17 N/A 7.3 HIGH
Improper access control in MPLocalService of MotionPhoto prior to version 4.1.51 allows local attackers to start privileged service.
CVE-2025-58481 1 Samsung 1 Motionphoto 2026-06-17 N/A 7.3 HIGH
Improper access control in MPRemoteService of MotionPhoto prior to version 4.1.51 allows local attackers to start privileged service.
CVE-2025-58480 1 Samsung 1 Android 2026-06-17 N/A 4.3 MEDIUM
Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
CVE-2025-58474 1 F5 2 Big-ip Advanced Web Application Firewall, Big-ip Application Security Manager 2026-06-17 N/A 5.3 MEDIUM
When BIG-IP Advanced WAF is configured on a virtual server with Server-Side Request Forgery (SSRF) protection or when an NGINX server is configured with App Protect Bot Defense, undisclosed requests can disrupt new client requests.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVE-2025-58473 2026-06-17 N/A 5.9 MEDIUM
An improper resource shutdown or release vulnerability has been identified in the Click Plus C2-03CPU-2 device running firmware version 3.60. The vulnerability allows an unauthenticated attacker to perform a denial-of-service attack by exhausting all available device sessions of the Click Programming Software.
CVE-2025-58472 1 Qnap 1 Qsync Central 2026-06-17 N/A 4.9 MEDIUM
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
CVE-2025-58471 1 Qnap 1 Qsync Central 2026-06-17 N/A 4.9 MEDIUM
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the vulnerability in the following version: Qsync Central 5.2.0.1 ( 2025/12/21 ) and later
CVE-2025-58470 1 Qnap 1 Qsync Central 2026-06-17 N/A 6.5 MEDIUM
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
CVE-2025-58469 1 Qnap 1 Qulog Center 2026-06-17 N/A 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: QuLog Center 1.8.2.927 ( 2025/09/17 ) and later
CVE-2025-58467 1 Qnap 1 Qsync Central 2026-06-17 N/A 6.5 MEDIUM
A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
CVE-2025-58466 1 Qnap 2 Qts, Quts Hero 2026-06-17 N/A 4.9 MEDIUM
A use of uninitialized variable vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to denial of service conditions, or modify control flow in unexpected ways. We have already fixed the vulnerability in the following versions: QTS 5.2.8.3332 build 20251128 and later QuTS hero h5.2.8.3321 build 20251117 and later