7.4

CVSS3.1

CVE-2025-20189 -

A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition. This vulnerability is due …

πŸ“… Published: May 7, 2025, 5:35 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 2:36 p.m.

6.8

CVSS3.0

CVE-2025-20181 -

A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the cha…

πŸ“… Published: May 7, 2025, 5:35 p.m. πŸ”„ Last Modified: Aug. 4, 2025, 6:51 p.m.

7.4

CVSS3.1

CVE-2025-20202 -

A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of access point (AP) Cisco Discovery Protocol (CDP) neighb…

πŸ“… Published: May 7, 2025, 5:35 p.m. πŸ”„ Last Modified: July 8, 2025, 5:17 p.m.

6.5

CVSS3.1

CVE-2025-20190 -

A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device. This vulnerability is due to insufficient access control of actions executed by lobby…

πŸ“… Published: May 7, 2025, 5:34 p.m. πŸ”„ Last Modified: July 31, 2025, 3:48 p.m.

10

CVSS4.0

CVE-2025-46828 - Unauthenticated SQL Injection on get_socios.php endpoint

WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3.0 in the endpoint `/html/socio/sistema/get_socios.php`, specifically in the query parameter. This issue allows attackers to inject and execute arbit…

πŸ“… Published: May 7, 2025, 5:34 p.m. πŸ”„ Last Modified: July 2, 2025, 4:30 p.m.

10

CVSS3.1

CVE-2025-20188 -

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. …

πŸ“… Published: May 7, 2025, 5:34 p.m. πŸ”„ Last Modified: June 23, 2025, 3:15 p.m.

4.3

CVSS3.1

CVE-2025-20214 -

A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This vulnerability exists because a subtle change in inner API call behavior c…

πŸ“… Published: May 7, 2025, 5:34 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 2:36 p.m.

4.7

CVSS3.1

CVE-2025-20137 -

A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the use of both an IPv4 AC…

πŸ“… Published: May 7, 2025, 5:31 p.m. πŸ”„ Last Modified: Aug. 5, 2025, 2:08 p.m.

7.1

CVSS3.1

CVE-2025-32821 -

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.

πŸ“… Published: May 7, 2025, 5:22 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

8.3

CVSS3.1

CVE-2025-32820 -

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.

πŸ“… Published: May 7, 2025, 5:20 p.m. πŸ”„ Last Modified: May 19, 2025, 3:12 p.m.
Total resulsts: 347725
Page 5358 of 34,773
Β« previous page Β» next page
Filters