7.3

CVSS3.1

CVE-2025-20210 - Cisco Catalyst Center Unprotected API Endpoint

A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication in an API endpoint. An attacker could e…

πŸ“… Published: May 7, 2025, 5:16 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 7:05 p.m.

5.7

CVSS4.0

CVE-2025-46551 - JRuby-OpenSSL has hostname verification disabled by default

JRuby-OpenSSL is an add-on gem for JRuby that emulates the Ruby OpenSSL native library. Starting in JRuby-OpenSSL version 0.12.1 and prior to version 0.15.4 (corresponding to JRuby versions starting in 9.3.4.0 prior to 9.4.12.1 and 10.0.0.0 prior to 10.0.0.1), when verifying SSL certificates, JRuby…

πŸ“… Published: May 7, 2025, 4:12 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 3:36 p.m.

8

CVSS3.1

CVE-2025-46827 - Graylog Allows Session Takeover via Insufficient HTML Sanitization

Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user session cookies by submitting an HTML form as part of an Event Definition Remediation Step field. For this attack to succeed, the attacker needs a user account with permiss…

πŸ“… Published: May 7, 2025, 3:29 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:29 p.m.

7.5

CVSS3.1

CVE-2024-47619 - tranport: TLS host name wildcard matching too lax

syslog-ng is an enhanced log daemo. Prior to version 4.8.2, `tls_wildcard_match()` matches on certificates such as `foo.*.bar` although that is not allowed. It is also possible to pass partial wildcards such as `foo.a*c.bar` which glib matches but should be avoided / invalidated. This issue could h…

πŸ“… Published: May 7, 2025, 3:12 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 10:33 a.m.

9.3

CVSS3.1

CVE-2025-2777 - SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.

πŸ“… Published: May 7, 2025, 2:53 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

9.3

CVSS3.1

CVE-2025-2776 - SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

πŸ“… Published: May 7, 2025, 2:50 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 6:33 p.m.

9.3

CVSS3.1

CVE-2025-2775 - SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

πŸ“… Published: May 7, 2025, 2:43 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 6:33 p.m.

4.3

CVSS3.1

CVE-2025-47692 - WordPress ContentStudio plugin <= 1.3.5 - Broken Access Control Vulnerability

Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contentstudio: from n/a through <= 1.3.5.

πŸ“… Published: May 7, 2025, 2:20 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

5.5

CVSS3.1

CVE-2025-47691 - WordPress Ultimate Member plugin <= 2.10.3 - Arbitrary Function Call vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3.

πŸ“… Published: May 7, 2025, 2:20 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

5.3

CVSS3.1

CVE-2025-47688 - WordPress Advanced File Manager plugin <= 5.3.1 - Broken Access Control to Notice Dismissal vulnera…

Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced File Manager: from n/a through <= 5.3.1.

πŸ“… Published: May 7, 2025, 2:20 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.
Total resulsts: 347734
Page 5361 of 34,774
Β« previous page Β» next page
Filters