Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-9855

The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_authors' shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
zuotian
Product
Enhanced BibliPlug
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9854

The A Simple Multilanguage Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'asmp-switcher' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
piupiiu
Product
A Simple Multilanguage Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9853

The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
optio
Product
Optio Dentistry
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9852

The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-schedule' shortcode in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
momostefan
Product
Yoga Schedule Momoyoga
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9851

The Appointmind plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'appointmind_calendar' shortcode in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
gentlesource
Product
Appointmind
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9850

The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'evenium_single_event' shortcode in all versions up to, and including, 1.3.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
evenium
Product
Evenium
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9849

The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_btn' shortcode in all versions up to, and including, 2.1.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
alimuzzamanalim
Product
Html Social share buttons
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9848

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
ScriptAndTools
Product
Real Estate Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9847

A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the argument uimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
ScriptAndTools
Product
Real Estate Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9846

Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry Inc. Inka.Net allows Command Injection. This issue affects Inka.Net: before 6.7.1.

PUBLISHED
Vendor
TalentSys Consulting Information Technology Industry Inc.
Product
Inka.Net
Provider severity
CRITICAL
Conflicts
0

CVE-2025-9845

A vulnerability has been found in code-projects Fruit Shop Management System 1.0. Affected by this vulnerability is an unknown functionality of the file products.php. Such manipulation of the argument product_code/gen_name/product_name/supplier leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
code-projects
Product
Fruit Shop Management System
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9844

Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable.This issue affects Salesforce CLI: before 2.106.6.

PUBLISHED
Vendor
Salesforce
Product
Salesforce CLI
Provider severity
HIGH
Conflicts
0

CVE-2025-9843

A flaw has been found in Das Parking Management System 停车场管理系统 6.2.0. Affected is an unknown function of the file /Operator/FindAll. This manipulation causes information disclosure. It is possible to initiate the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
Das
Product
Parking Management System 停车场管理系统
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9842

A vulnerability was detected in Das Parking Management System 停车场管理系统 6.2.0. This impacts an unknown function of the file /Operator/Search. The manipulation results in information disclosure. The attack may be performed from remote. The exploit is now public and may be used.

PUBLISHED
Vendor
Das
Product
Parking Management System 停车场管理系统
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9841

A security vulnerability has been detected in code-projects Mobile Shop Management System 1.0. This affects an unknown function of the file AddNewProduct.php. The manipulation of the argument ProductImage leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
code-projects
Product
Mobile Shop Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9840

A weakness has been identified in itsourcecode Sports Management System 1.0. The impacted element is an unknown function of the file /Admin/gametype.php. Executing manipulation of the argument code can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
itsourcecode
Product
Sports Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9839

A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
itsourcecode
Product
Student Information Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9838

A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
itsourcecode
Product
Student Information Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9837

A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the argument studentId causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
itsourcecode
Product
Student Information Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9836

A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderId results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
macrozheng
Product
mall
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9835

A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
macrozheng
Product
mall
Provider severity
MEDIUM
Conflicts
2

CVE-2025-9834

A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of the argument Username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
PHPGurukul
Product
Small CRM
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9833

A vulnerability was detected in SourceCodester Online Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/login.php. Performing manipulation of the argument uname results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Online Farm Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9832

A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the file /routers/register-router.php. Such manipulation of the argument phone leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Food Ordering Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9831

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of the file /admin/edit-services.php. This manipulation of the argument sername causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
PHPGurukul
Product
Beauty Parlour Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9830

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of the file /admin/add-customer-services.php. The manipulation of the argument sids[] results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
PHPGurukul
Product
Beauty Parlour Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9829

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /signup.php. The manipulation of the argument mobilenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. Other parameters might be affected as well.

PUBLISHED
Vendor
PHPGurukul
Product
Beauty Parlour Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9828

A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Tenda
Product
CP6
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2025-9826

Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users.

PUBLISHED
Vendor
M-Files Corporation
Product
Hubshare
Provider severity
HIGH
Conflicts
0

CVE-2025-9825

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9824

ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when: * A valid username was pro

PUBLISHED
Vendor
Mautic
Product
Mautic
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9823

SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoi

PUBLISHED
Vendor
Mautic
Product
Mautic
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9822

SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.

PUBLISHED
Vendor
Mautic
Product
Mautic
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9821

SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/  for more potential impact. Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forge

PUBLISHED
Vendor
Mautic
Product
Mautic
Provider severity
LOW
Conflicts
0

CVE-2025-9820

A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privileg

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Siemens
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, RHEL-8 based Middleware Containers, RHEL-8 based Middleware Containers, Red Hat Ceph Storage 8, Red Hat Update Infrastructure 5, RHEL-8 based Middleware Containers, Red Hat Enterprise Linux 10, RHEL-8 based Middleware Containers, Red Hat Update Infrastructure 5, Red Hat Insights proxy 1.5, Red Hat Discovery 2, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Update Infrastructure 5, RHEL-8 based Middleware Containers, Red Hat Enterprise Linux 8, RHEL-8 based Middleware Containers, Red Hat Enterprise Linux 7, Red Hat Discovery 2, Red Hat Update Infrastructure 5, Red Hat Hardened Images, Red Hat Enterprise Linux 9, RHEL-8 based Middleware Containers, SIMATIC CN 4100
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9818

A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided by OMRON SOCIAL SOLUTIONS Co., Ltd., where the executable file paths of Windows services are not enclosed in quotation marks. If the installation folder path of this product contains spaces, there is a possibility that unauthorized files may be executed under the service privileges by using paths containing spaces.

PUBLISHED
Vendor
OMRON SOCIAL SOLUTIONS CO., Ltd., OMRON SOCIAL SOLUTIONS CO., Ltd., OMRON SOCIAL SOLUTIONS CO., Ltd., OMRON SOCIAL SOLUTIONS CO., Ltd., OMRON SOCIAL SOLUTIONS CO., Ltd.
Product
Simple Shutdown Software, PowerAttendant Standard Edition, PowerAttendant Basic Edition, PowerAct Pro <Master Agent>, PowerAct Pro <Slave Agent>
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9817

SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service

PUBLISHED
Vendor
Wireshark Foundation
Product
Wireshark
Provider severity
HIGH
Conflicts
0

CVE-2025-9816

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
veronalabs
Product
WP Statistics – Simple, privacy-friendly Google Analytics alternative
Provider severity
HIGH
Conflicts
0

CVE-2025-9815

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function of the file PrivilegeHelper/PrivilegeHelper.swift of the component NSXPCListener. This manipulation causes missing authentication. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be exploited.

PUBLISHED
Vendor
alaneuler
Product
batteryKid
Provider severity
HIGH
Conflicts
2

CVE-2025-9814

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.

PUBLISHED
Vendor
PHPGurukul
Product
Beauty Parlour Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9813

A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /goform/SetSambaConf. The manipulation of the argument samba_userNameSda leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
Tenda
Product
CH22
Provider severity
HIGH
Conflicts
2

CVE-2025-9812

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Executing manipulation of the argument cmdinput can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Tenda
Product
CH22
Provider severity
HIGH
Conflicts
2

CVE-2025-9811

A vulnerability was found in Campcodes Farm Management System 1.0. This affects an unknown part of the file /reviewInput.php. Performing manipulation of the argument rating results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
Campcodes
Product
Farm Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-9810

TOCTOU  in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path and subsequent chmod() on the same path.

PUBLISHED
Vendor
antirez
Product
linenoise
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9809

Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file path exceeding PATH_MAX_LENGTH that is copied using memcpy into a fixed-size buffer.

PUBLISHED
Vendor
libretro
Product
libretro-common
Provider severity
HIGH
Conflicts
0

CVE-2025-9808

The The Events Calendar plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.15.2 via the REST endpoint. This makes it possible for unauthenticated attackers to extract information about password-protected vendors or venues.

PUBLISHED
Vendor
stellarwp
Product
The Events Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2025-9807

The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all versions up to, and including, 6.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PUBLISHED
Vendor
stellarwp
Product
The Events Calendar
Provider severity
HIGH
Conflicts
0

CVE-2025-9806

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation with the input Fireitup causes hard-coded credentials. The attack can only be executed locally. A high degree of complexity is needed for the attack. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Tenda
Product
F1202
Provider severity
LOW
Conflicts
2

CVE-2025-9805

A vulnerability was found in SimStudioAI sim up to 51b1e97fa22c48d144aef75f8ca31a74ad2cfed2. This issue affects some unknown processing of the file apps/sim/app/api/proxy/image/route.ts. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The pat

PUBLISHED
Vendor
SimStudioAI
Product
sim
Provider severity
MEDIUM
Conflicts
1

CVE-2025-9804

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information. This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.

PUBLISHED
Vendor
WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2, WSO2
Product
WSO2 Open Banking AM, org.wso2.carbon.identity.framework:org.wso2.carbon.identity.application.mgt, WSO2 Data Analytics Server, WSO2 Enterprise Service Bus Analytics, WSO2 Open Banking IAM, WSO2 Identity Server, WSO2 Universal Gateway, org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.rest.api.util, WSO2 Identity Server as Key Manager, WSO2 Traffic Manager, WSO2 API Control Plane, WSO2 Open Banking KM, org.wso2.carbon:org.wso2.carbon.base, org.wso2.carbon.identity.workflow.user:org.wso2.carbon.user.mgt.workflow, org.wso2.carbon.extension.identity.authenticator.outbound.totp:org.wso2.carbon.extension.identity.authenticator.totp.connector, API Manager Analytics, org.wso2.carbon:org.wso2.carbon.server.admin, WSO2 Identity Server Analytics, WSO2 Enterprise Integrator, WSO2 Enterprise Mobility Manager, WSO2 API Manager
Provider severity
CRITICAL, HIGH
Conflicts
2