9

CVSS4.0

CVE-2025-34064 - OneLogin AD Connector Log S3 Bucket Hijack Leading to Cross-Tenant Data Leakage

A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An attacker who registers this unclaimed bucket can begin receiving log files from other OneLogin tenants. The…

📅 Published: July 1, 2025, 2:49 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-34063 - OneLogin AD Connector JWT Authentication Bypass via Exposed Signing Key

A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint. An attacker in possession of the signing key can craft valid JWT tokens impersonating arbitrary users …

📅 Published: July 1, 2025, 2:49 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS4.0

CVE-2025-34062 - OneLogin AD Connector API Credential and Signing Key Exposure

An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which may be retrievable from host registry keys or improperly secured logs—can retrieve a plaintext respons…

📅 Published: July 1, 2025, 2:49 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2025-34060 - Monero Forum Remote Code Execution via Arbitrary File Read and Cookie Forgery

A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the /get/image/ endpoint. The application passes a user-supplied link parameter directly to file_get_contents() without validation. MIME type checks using…

📅 Published: July 1, 2025, 2:49 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-34059 - Dahua Smart Cloud Gateway Registration Management Platform SQL Injection

An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements an…

📅 Published: July 1, 2025, 2:48 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-34058 - Hikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File Re…

Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these credentials, an attacker can exploit an arbitrary file read vulnerability in the /systemLog/downFile.php endpo…

📅 Published: July 1, 2025, 2:48 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2025-34066 - AVTECH IP camera, DVR, and NVR Devices Unauthenticated Information Disclosure

An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.

📅 Published: July 1, 2025, 2:47 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-34065 - AVTECH IP camera, DVR, and NVR Devices Authentication Bypass via /nobody URL Path

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.

📅 Published: July 1, 2025, 2:47 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-34056 - AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution

An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without pr…

📅 Published: July 1, 2025, 2:46 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS4.0

CVE-2025-34055 - AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution

An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the strCmd parameter. This input is executed direc…

📅 Published: July 1, 2025, 2:46 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4825 of 34,919
« previous page » next page
Filters