Latest CVE Feed
-
8.8
HIGHCVE-2022-37912
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. ... Read more
- EPSS Score: %0.38
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
8.8
HIGHCVE-2022-37903
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating s... Read more
- EPSS Score: %0.28
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2023-6683
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and had the chance to initialize the clipboard peer, leading to a N... Read more
- EPSS Score: %0.08
- Published: Jan. 12, 2024
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2023-44221
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulner... Read more
Affected Products : sma_210_firmware sma_410_firmware sma_500v_firmware sma_200_firmware sma_400_firmware sma100_firmware sma_210 sma_410 sma_500v sma_200 +1 more products- Actively Exploited
- EPSS Score: %15.16
- Published: Dec. 05, 2023
- Modified: May. 02, 2025
-
7.2
HIGHCVE-2022-37902
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. ... Read more
- EPSS Score: %0.43
- Published: Dec. 12, 2022
- Modified: May. 02, 2025
-
8.1
HIGHCVE-2022-24309
A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8.18.16), Mendix Runtime V9 (All versions < V9.13 only with Runtime Custom Setting *DataStorage.UseNewQueryHandler* set to False). If an... Read more
Affected Products : mendix- EPSS Score: %0.16
- Published: Mar. 08, 2022
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2016-1585
In all versions of AppArmor mount rules are accidentally widened when compiled.... Read more
- EPSS Score: %0.08
- Published: Apr. 22, 2019
- Modified: May. 02, 2025
-
1.0
LOWCVE-2025-3301
DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to a lack of hardware and software support. A successful DPA attack may result in exposure of confident... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
5.3
MEDIUMCVE-2024-9877
: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
9.3
CRITICALCVE-2025-40619
Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to reach private areas and/or areas intended for other roles.... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
9.4
CRITICALCVE-2025-0520
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.... Read more
Affected Products : showdoc- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
4.9
MEDIUMCVE-2025-46344
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime` when generating a JWE token for the session. As a result, the JWE does not... Read more
Affected Products : nextjs-auth0- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
8.6
HIGHCVE-2025-29906
Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementation of getty for the `tty` configuration directive that can bypass `/bin/login`, i.e., a user can log in as any user without authenticati... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
6.3
MEDIUMCVE-2025-46552
KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a vulnerability was identified where user data, including email addresses and Discord ... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
-
5.0
MEDIUMCVE-2025-24339
A vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to conduct various attacks against users of the vulnerable system, including web cache poisoning or Man-in-the-Middle (MitM), via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2025-24341
A vulnerability in the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to induce a Denial-of-Service (DoS) condition on the device via multiple crafted HTTP requests. In the worst case, a full power cycle is needed to r... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
5.4
MEDIUMCVE-2025-24343
A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary files in arbitrary file system paths via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
6.3
MEDIUMCVE-2025-24345
A vulnerability in the “Hosts” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the “hosts” file in an unintended manner via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
6.5
MEDIUMCVE-2025-24347
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to manipulate the network configuration file via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025
-
7.1
HIGHCVE-2025-24350
A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary certificates in arbitrary file system paths via a crafted HTTP request.... Read more
Affected Products :- Published: Apr. 30, 2025
- Modified: May. 02, 2025