7.3
CVE-2025-53189 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
7.3
CVE-2025-53188 - Unauthenticated Credentials Exposure
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.4
CVE-2025-25229 -
Omnissa Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) Vulnerability.Β A malicious actor with user privileges may be able to access restricted internal system information, potentially enabling enumeration of internal network resources.
7.5
CVE-2025-25231 -
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability.Β A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints.
8
CVE-2025-54063 - Cherry Studio One-click Remote Code Execution Vulnerability through Custom URL Handling
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution vulnerability through the custom URL handling. An attacker can exploit this by hosting a malicious website or embedding a specially crafted URL on anyβ¦
9.3
CVE-2025-53187 - Unauthenticated RCE
Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. This vulnerability may allow an attacker to change the system time, access files, and make function calls without prior β¦
5.1
CVE-2025-8866 - yugabytedb: YugabyteDB authentication bypass
YugabyteDB Anywhere web server does not properly enforce authentication for the /metamaster/universe API endpoint. An unauthenticated attacker could exploit this flaw to obtain server networking configuration details, including private and public IP addresses and DNS records.
9.4
CVE-2012-10040 - Openfiler v2.x NetworkCard Command Execution
Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to instantiate a NetworkCard object, whose constructor in network.inc calls exec() with unsanitized input. An authenticated attacker can exploit this to execute arbitrary commands as the β¦
9.4
CVE-2012-10039 - ZEN Load Balancer Filelog Command Execution
ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call without sanitation. An authenticated attacker can inject arbitrary shell commands, resulting in remote code executioβ¦
9.3
CVE-2012-10038 - Auxilium RateMyPet Arbitrary File Upload RCE
Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files. These files are stored in a web-accessible /banners/ dβ¦