5.3

CVSS4.0

CVE-2025-8665 - agno-agi agno Model Context Protocol mcp.py MultiMCPTools os command injection

A vulnerability, which was classified as critical, has been found in agno-agi agno up to 1.7.5. This issue affects the function MCPTools/MultiMCPTools in the library libs/agno/agno/tools/mcp.py of the component Model Context Protocol Handler. The manipulation of the argument command leads to os comโ€ฆ

๐Ÿ“… Published: Aug. 6, 2025, 5:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-20215 - Cisco Webex Meeting Client Join Certificate Validation Vulnerability

A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network-proximate attacker to complete a meeting-join process in place of an intended targeted user, provided the requisite conditions were satisfied. Cisco has addressed this vulnerabilโ€ฆ

๐Ÿ“… Published: Aug. 6, 2025, 4:17 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-20332 - Cisco Identity Services Engine Authorization Bypass Vulnerability

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit thiโ€ฆ

๐Ÿ“… Published: Aug. 6, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-20331 - Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabiliy

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a stored XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based managemeโ€ฆ

๐Ÿ“… Published: Aug. 6, 2025, 4:14 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8

CVSS3.1

CVE-2025-53786 - Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identifiedโ€ฆ

๐Ÿ“… Published: Aug. 6, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Feb. 27, 2026, 3:38 a.m.

3.7

CVSS3.1

CVE-2024-8244 - Walk/WalkDir in path/filepath susceptible to symlink race

The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.

๐Ÿ“… Published: Aug. 6, 2025, 3:32 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-48394 -

An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the CLI. This security issue has been fixed in the latest version which is available on the Eaton download center.

๐Ÿ“… Published: Aug. 6, 2025, 3:25 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2025-48393 -

The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version ofย Eaton G4 PDU which is available on the Eaton doโ€ฆ

๐Ÿ“… Published: Aug. 6, 2025, 3:25 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2024-52885 - Path Traversal

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway.

๐Ÿ“… Published: Aug. 6, 2025, 2:45 p.m. ๐Ÿ”„ Last Modified: Aug. 27, 2025, 2:21 p.m.

6.5

CVSS3.1

CVE-2025-2028 - Lack of TLS validation

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

๐Ÿ“… Published: Aug. 6, 2025, 2:44 p.m. ๐Ÿ”„ Last Modified: Aug. 27, 2025, 2:13 p.m.
Total resulsts: 349182
Page 4383 of 34,919
ยซ previous page ยป next page
Filters