5.3

CVSS4.0

CVE-2025-34243 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxFwRulesController.ajaxNetworkFwRulesAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:47 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:47 p.m.

8.6

CVSS4.0

CVE-2025-34242 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxNetworkController.ajaxAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:46 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:46 p.m.

5.3

CVSS4.0

CVE-2025-34241 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AjaxDeviceController.ajaxDeviceAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:45 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:45 p.m.

8.6

CVSS4.0

CVE-2025-34240 - Advantech WebAccess/VPN < 1.1.5 SQL Injection via AppManagementController.appUpgradeAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.

📅 Published: Nov. 6, 2025, 7:45 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:45 p.m.

8.6

CVSS4.0

CVE-2025-34239 - Advantech WebAccess/VPN < 1.1.5 Command Injection in AppManagementController.appUpgradeAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.

📅 Published: Nov. 6, 2025, 7:44 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:44 p.m.

6.9

CVSS4.0

CVE-2025-34238 - Advantech WebAccess/VPN < 1.1.5 Path Traversal via AjaxStandaloneVpnClientsController.ajaxDownloadR…

Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() that allows an authenticated network administrator to cause the application to read and return the contents of arbitrary files the web …

📅 Published: Nov. 6, 2025, 7:43 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:43 p.m.

6.3

CVSS4.0

CVE-2025-34237 - Advantech WebAccess/VPN < 1.1.5 Stored XSS via StandaloneVpnClientsController.addStandaloneVpnClien…

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the…

📅 Published: Nov. 6, 2025, 7:40 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:40 p.m.

6.2

CVSS4.0

CVE-2025-34236 - Advantech WebAccess/VPN < 1.1.5 Stored XSS via NetworksController.addNetworkAction()

Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's b…

📅 Published: Nov. 6, 2025, 7:39 p.m. 🔄 Last Modified: Nov. 6, 2025, 7:39 p.m.

6.7

CVSS3.1

CVE-2025-22397 -

Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain an Improper Limitation of a Pathname to a Restricted Directory ('Pat…

📅 Published: Nov. 6, 2025, 6:46 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:46 p.m.

7.3

CVSS3.1

CVE-2024-25621 - containerd affected by a local privilege escalation via wide permissions on CRI directory

containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability. Directory paths `/var/lib/containerd`, `/run/containerd/io.containerd.grpc…

📅 Published: Nov. 6, 2025, 6:36 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:36 p.m.
Total resulsts: 317261
Page 5 of 31,727
« previous page » next page
Filters