8.7

CVSS4.0

CVE-2025-58764 - Claude Code rg command had Command Injection that allowed bypass of user approval prompt for comman…

Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to a bypass of the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted content into a Claude …

πŸ“… Published: Sept. 10, 2025, 3:06 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:46 p.m.

7

CVSS3.1

CVE-2025-10231 - N-central Incorrect Default Permissions could lead to Privilege Escalation

An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions.

πŸ“… Published: Sept. 10, 2025, 1:34 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

5.1

CVSS4.0

CVE-2025-10227 - Lack of Encryption in Object Archive in AxxonSoft Axxon One (C-Werk) before 2.0.8

Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon OneΒ (C-Werk) before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in plaintext via lack of encryption a…

πŸ“… Published: Sept. 10, 2025, 12:39 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 1:48 p.m.

9.3

CVSS4.0

CVE-2025-10226 - PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier to Address M…

Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via exploitation of multiple known CVEs pres…

πŸ“… Published: Sept. 10, 2025, 12:38 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 1:54 p.m.

8.7

CVSS4.0

CVE-2025-10225 - Incorrect Memory Allocation in OpenSSL-Based Session Module in AxxonSoft Axxon One (C-Werk)

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cause application crashes or unpredictable behavior via triggerin…

πŸ“… Published: Sept. 10, 2025, 12:37 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 12:15 p.m.

5.3

CVSS4.0

CVE-2025-10224 - Incorrect Evaluation of LDAP Nested Groups during Login in AxxonSoft Axxon One (C-Werk)

Improper Authentication (CWE-287) in the LDAP authentication engine in AxxonSoft Axxon One (C-Werk) 2.0.2 and earlier on Windows allows a remote authenticated user to be denied access or misassigned roles via incorrect evaluation of nested LDAP group memberships during login.

πŸ“… Published: Sept. 10, 2025, 12:36 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 12:15 p.m.

5.3

CVSS4.0

CVE-2025-10223 - Improper Session Cleanup on Role Removal in Web Admin Panel in AxxonSoft Axxon One (C-Werk)

Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration.

πŸ“… Published: Sept. 10, 2025, 12:35 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 12:15 p.m.

4.8

CVSS4.0

CVE-2025-10222 - Sensitive Information Disclosure in Diagnostic Dumps in AxxonSoft Axxon One VMS

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS (C-Werk) 2.0.0 through 2.0.1 on Windows allows a local attacker to obtain licensing-related information such as timestamps, license states, and registry values via readin…

πŸ“… Published: Sept. 10, 2025, 12:34 p.m. πŸ”„ Last Modified: Oct. 8, 2025, 12:15 p.m.

6.7

CVSS4.0

CVE-2025-10221 - Hardcoded Password Exposure in AxxonNet (C-WerkNet) ARP Agent Logs

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via reading TRACE log files containing serialized JSON with passwords.

πŸ“… Published: Sept. 10, 2025, 12:31 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 2:24 p.m.

9.3

CVSS4.0

CVE-2025-10220 - Outdated Third-Party NuGet Packages in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4

Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploitation of vulnerable third-party packages such as Google.Protob…

πŸ“… Published: Sept. 10, 2025, 12:28 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 2:34 p.m.
Total resulsts: 349182
Page 3918 of 34,919
Β« previous page Β» next page
Filters