8.5

CVSS4.0

CVE-2024-9876 - Application is vulnerable to Privilege escalation

: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

๐Ÿ“… Published: April 30, 2025, 6:31 p.m. ๐Ÿ”„ Last Modified: May 2, 2025, 1:53 p.m.

5.3

CVSS3.1

CVE-2025-46554 - XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API

XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0, anyone can access the metadata of any attachment in the wiki using the wiki attachment REST endpoint. Thโ€ฆ

๐Ÿ“… Published: April 30, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 5:53 p.m.

8.4

CVSS4.0

CVE-2025-46557 - Any user with view access to the XWiki space can change the authenticator

XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, a user who can access pages located in the XWiki space (by default, anyone) can access the page XWiki.Authentication.Administratiโ€ฆ

๐Ÿ“… Published: April 30, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: Sept. 3, 2025, 5:52 p.m.

9.1

CVSS3.1

CVE-2025-46558 - org.xwiki.contrib.markdown:syntax-markdown-commonmark12 vulnerable to XSS via Markdown content

XWiki Contrib's Syntax Markdown allows importing Markdown content into wiki pages and creating wiki content in Markdown. In versions starting from 8.2 to before 8.9, the Markdown syntax is vulnerable to cross-site scripting (XSS) through HTML. In particular, using Markdown syntax, it's possible forโ€ฆ

๐Ÿ“… Published: April 30, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: Aug. 26, 2025, 4:28 p.m.

6.3

CVSS3.1

CVE-2025-24887 - OpenCTI bypass of protected attribute update

OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user to change attributes that are intended to be unmodifiable by the user. It is possible to toggle the `external` flag on/off and changeโ€ฆ

๐Ÿ“… Published: April 30, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: May 19, 2025, 11:51 a.m.

8.2

CVSS4.0

CVE-2025-32777 - Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin

Volcano is a Kubernetes-native batch scheduling system. Prior to versions 1.11.2, 1.10.2, 1.9.1, 1.11.0-network-topology-preview.3, and 1.12.0-alpha.2, attacker compromise of either the Elastic service or the extender plugin can cause denial of service of the scheduler. This is a privilege escalatiโ€ฆ

๐Ÿ“… Published: April 30, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: May 2, 2025, 1:53 p.m.

5.8

CVSS4.0

CVE-2025-46331 - OpenFGA Authorization Bypass

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. OpenFGA v1.8.10 to v1.3.6 (Helm chart <= openfga-0.2.28, docker <= v.1.8.10) are vulnerable to authorization bypass when certain Check and ListObject calls are executed. โ€ฆ

๐Ÿ“… Published: April 30, 2025, 6:27 p.m. ๐Ÿ”„ Last Modified: Dec. 31, 2025, 3:06 p.m.

2.1

CVSS4.0

CVE-2024-47784 - Unverified Password Change

Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier.

๐Ÿ“… Published: April 30, 2025, 6:17 p.m. ๐Ÿ”„ Last Modified: May 2, 2025, 1:53 p.m.

5.3

CVSS4.0

CVE-2025-4135 - Netgear WG302v2 ui_get_input_value command injection

A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The manipulation of the argument host leads to command injection. The attack may be launched remotely. The vendor was contacted early about this disclosureโ€ฆ

๐Ÿ“… Published: April 30, 2025, 5:31 p.m. ๐Ÿ”„ Last Modified: June 24, 2025, 9:44 a.m.

5.5

CVSS3.1

CVE-2025-24091 -

An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.

๐Ÿ“… Published: April 30, 2025, 5:21 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 6:17 p.m.
Total resulsts: 343168
Page 5022 of 34,317
ยซ previous page ยป next page
Filters