CVE-2025-10847None▾ SunlitDX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
DX Unified Infrastructure Management (Nimsoft/UIM) and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-36351Medium· 4.3IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions.
CVE-2025-11136Medium· 4.7A flaw has been found in YiFang CMS up to 2.0.2
CVE-2018-12120High· 8.1Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default
CVE-2025-62510High· 8.1FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations
CVE-2025-62509High· 8.1FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations
CVE-2025-11908Medium· 6.3A security flaw has been discovered in Shenzhen Ruiming Technology Streamax Crocus 1.3.40