5.4

CVSS3.1

CVE-2025-20168 - Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 4:19 p.m. ๐Ÿ”„ Last Modified: July 23, 2025, 4:11 p.m.

5.4

CVSS3.1

CVE-2025-20167 - Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 4:19 p.m. ๐Ÿ”„ Last Modified: July 23, 2025, 4:11 p.m.

5.4

CVSS3.1

CVE-2025-20166 - Cisco Common Services Platform Collector Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 4:19 p.m. ๐Ÿ”„ Last Modified: July 23, 2025, 3:47 p.m.

4.8

CVSS3.1

CVE-2025-20126 - Cisco ThousandEyes Endpoint Agent Certificate Validation Vulnerability

A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information. This vulnerability exists because the affected software does not properly validate certifโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 4:09 p.m. ๐Ÿ”„ Last Modified: July 22, 2025, 3:33 p.m.

4.8

CVSS3.1

CVE-2025-20123 - Cisco Crosswork Network Controller Stored Cross-Site Scripting Vulnerability

Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users of the interface of an affected system. These vulnerabilities exist because the web-basedโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 4:09 p.m. ๐Ÿ”„ Last Modified: July 23, 2025, 3:39 p.m.

9.8

CVSS3.1

CVE-2025-22137 - Arbitrary File Overwrite via HTTP POST in Pingvin Share

Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, including sensitive system files, via HTTP POST requests. The issuโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 4:08 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2025, 7:28 p.m.

8.6

CVSS4.0

CVE-2025-22136 - Tabby has a TCC Bypass via Misconfigured Node Fuses

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection vectors even though the โ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 4:02 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2025, 7:25 p.m.

5.3

CVSS4.0

CVE-2025-22130 - Soft Serve allows path traversal attacks

Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can modify, delete, and arbitrarily repositories as if they were an admin user without expโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 3:43 p.m. ๐Ÿ”„ Last Modified: Nov. 6, 2025, 10:04 p.m.

8.8

CVSS3.1

CVE-2024-55656 - RedisBloom Integer Overflow Remote Code Execution Vulnerability

RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloom, which is a module used in Redis. The integer overflow vulnerability allows an attacker (a redis client which knows the password) to allocate memory in the heap lesser than the โ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 3:38 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2025, 4:15 p.m.

7

CVSS3.1

CVE-2024-51737 - RediSearch Integer Overflow with LIMIT or KNN arguments can lead to RCE

RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticated redis user executing FT.SEARCH or FT.AGGREGATE with a specially crafted LIMIT command argument, or FT.SEARCH with a specially crafted KNN command argument, can trigger an integeโ€ฆ

๐Ÿ“… Published: Jan. 8, 2025, 3:27 p.m. ๐Ÿ”„ Last Modified: Jan. 8, 2025, 4:15 p.m.
Total resulsts: 343996
Page 6705 of 34,400
ยซ previous page ยป next page
Filters