Latest CVE Feed
-
9.1
CVSS31CVE-2025-26847
An issue was discovered in Znuny before 7.1.5. When generating a support bundle, not all passwords are masked.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
9.8
CVSS31CVE-2025-26845
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
9.8
CVSS31CVE-2025-26844
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
7.5
CVSS31CVE-2025-26842
An issue was discovered in Znuny through 7.1.3. If access to a ticket is not given, the content of S/MIME encrypted e-mail messages is visible to users with access to the CommunicationLog.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
10.0
CVSS31CVE-2025-0505
On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state... Read more
Affected Products : cloudvision_portal- Published: May. 08, 2025
- Modified: May. 08, 2025
-
8.7
CVSS31CVE-2024-8100
On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
9.1
CVSS31CVE-2024-12378
On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.... Read more
Affected Products : cloudvision_portal- Published: May. 08, 2025
- Modified: May. 08, 2025
-
10.0
CVSS31CVE-2024-11186
On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-pre... Read more
Affected Products : cloudvision_portal- Published: May. 08, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-4098
Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could allow an attacker to disclose information and execute arbitrary code on affected installations of Cscape.... Read more
Affected Products : cscape- Published: May. 08, 2025
- Modified: May. 08, 2025
-
5.5
CVSS31CVE-2025-30102
Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.1.0, contains an out-of-bounds write vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to denial of service.... Read more
Affected Products : powerscale_onefs- Published: May. 08, 2025
- Modified: May. 08, 2025
-
4.4
CVSS31CVE-2025-30101
Dell PowerScale OneFS, versions 9.8.0.0 through 9.10.1.0, contain a time-of-check time-of-use (TOCTOU) race condition vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to denial of service a... Read more
Affected Products : powerscale_onefs- Published: May. 08, 2025
- Modified: May. 08, 2025
-
7.5
CVSS31CVE-2025-1948
In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to alloca... Read more
Affected Products : jetty- Published: May. 08, 2025
- Modified: May. 08, 2025
-
7.2
CVSS31CVE-2024-13009
In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.... Read more
Affected Products : jetty- Published: May. 08, 2025
- Modified: May. 08, 2025
-
3.1
CVSS31CVE-2025-4132
Rapid7 Corporate Website prior to May 2nd 2025, suffered from a URL Redirection to Untrusted Site ('Open Redirect') vulnerability whereby, due to misconfigured headers, an attacker could successfully redirect users to a malicious site of their control. T... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
6.8
CVSS31CVE-2025-4043
An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-45847
ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the formWsc function.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-45846
ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the formBTClinetSetting function.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-45845
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid5g parameter in the setWiFiEasyGuestCfg function.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-45844
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiBasicCfg function.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-45843
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the ssid parameter in the setWiFiGuestCfg function.... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 08, 2025