proCertum SmartSign contains an XML External Entity (XXE) vulnerability. The issue allows for Server-Side Request Forgery (SSRF) and potentially enables reading of local files, depending on the parser's configuration. The vulnerability is triggered by previewing a crafted signature file in the file selection window, before opening it. This issue was fixed in version 9.4.3.90. The vulnerability can lead to [truncated]
CVE-2025-66955 is a medium-severity local file inclusion issue affecting the Contact Plan, E-Mail, SMS, and Fax components in Asseco SEE Live 2.0. The issue is described as exposure through the path parameter in the downloadAttachment and downloadAttachmentFromPath API calls, allowing remote authenticated users to access files on the host. The CVE was published on 2026-03-12 and last modified on 2026-05-1 [truncated]