2.2
CVE-2025-14840 - drupal: Drupal Http Client Manager: Information disclosure due to insufficient data separation
No description is available for this CVE.
10
CVE-2025-20393 - Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerabβ¦
Cisco is aware of a potential vulnerability. Cisco is currently investigating and will update these details as appropriate as more information becomes available.
6.5
CVE-2025-26381 - OpenBlue Mobile Web Application configuration issue for optional for OpenBlue Workplace (formerly Fβ¦
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information.
8.7
CVE-2025-43873 - iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application commandβ¦
Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the device.
8.7
CVE-2025-14727 - NGINX Ingress Controller vulnerability
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-targetΒ annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
10
CVE-2025-44005 - github.com/smallstep/certificates: github.com/smallstep/certificates: Authorization bypass allows uβ¦
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create certificates without completing certain protocol authorization checks.
0.6
CVE-2025-14266 - CSRF in Ercom Cryptobox administration console
CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox administrator. The attack requires the administrator to browse a malicious web site or to click a link while he has an open session on the administration console.
0.0
CVE-2025-14828 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
7.1
CVE-2025-61736 - iSTAR- Improper Validation of Certificate Expiration
Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the certificate expires.
7.2
CVE-2025-14097 - Remote Code Execution Vulnerability in Radiometer Products
A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthorized device management when specific internal conditions are met. Exploitation requires that a remote connection is established with additional information obtained through other β¦