Latest CVE Feed
-
4.3
CVSS31CVE-2025-20214
A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This vulnerability exists because ... Read more
Affected Products : ios_xe- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.7
CVSS31CVE-2025-20216
A vulnerability in the web interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to inject HTML into the browser of an authenticated user. This vulnerability is due to improper saniti... Read more
Affected Products : catalyst_sd-wan_manager- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.3
CVSS31CVE-2025-20221
A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an af... Read more
Affected Products : ios_xe- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.7
CVSS31CVE-2025-20223
A vulnerability in Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to read and modify data in a repository that belongs to an internal service of an affected device. This vulnerability is due to insuffici... Read more
Affected Products : dna_center- Published: May. 07, 2025
- Modified: May. 08, 2025
-
8.8
CVSS31CVE-2025-32819
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.... Read more
Affected Products : sma100_firmware- Published: May. 07, 2025
- Modified: May. 08, 2025
-
3.1
CVSS31CVE-2025-46824
The Discourse Code Review Plugin allows users to review GitHub commits on Discourse. Prior to commit eed3a80, an attacker can execute arbitrary JavaScript on users' browsers by posting links to malicious GitHub commits. This problem is patched in commit e... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.5
CVSS31CVE-2025-47203
dbclient in Dropbear SSH before 2025.88 allows command injection via an untrusted hostname argument, because a shell is used.... Read more
Affected Products : dropbear_ssh- Published: May. 07, 2025
- Modified: May. 08, 2025
-
8.1
CVSS31CVE-2025-26168
IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configurati... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-30147
Besu Native contains scripts and tooling that is used to build and package the native libraries used by the Ethereum client Hyperledger Besu. Besu 24.7.1 through 25.2.2, corresponding to besu-native versions 0.9.0 through 1.2.1, have a potential consensus... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
3.5
CVSS31CVE-2023-7303
A vulnerability, which was classified as problematic, was found in q2apro q2apro-on-site-notifications up to 1.4.6. This affects the function process_request of the file q2apro-onsitenotifications-page.php. The manipulation leads to cross site scripting. ... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.5
CVSS31CVE-2025-36525
When a BIG-IP APM virtual server is configured to use a PingAccess profile, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.... Read more
Affected Products : big-ip_access_policy_manager- Published: May. 07, 2025
- Modified: May. 08, 2025
-
7.5
CVSS31CVE-2025-41399
When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not eva... Read more
- Published: May. 07, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-46826
insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal ri... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
-
6.5
CVSS31CVE-2025-0936
On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly... Read more
Affected Products : eos- Published: May. 07, 2025
- Modified: May. 08, 2025
-
4.2
CVSS31CVE-2025-32441
Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack sessio... Read more
Affected Products : rack- Published: May. 07, 2025
- Modified: May. 08, 2025
-
5.3
CVSS31CVE-2025-35939
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and... Read more
Affected Products : craft_cms- Published: May. 07, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2024-55651
i-Educar is free, fully online school management software. Version 2.9 of the application fails to properly validate and sanitize user supplied input, leading to a stored cross-site scripting vulnerability that resides within the user type (Tipo de Usuári... Read more
Affected Products : i-educar- Published: May. 08, 2025
- Modified: May. 08, 2025
-
5.3
CVSS31CVE-2025-32873
An issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function is vulnerable to a potential denial-of-service (slow performance) when processing inputs containing large sequences of... Read more
Affected Products : django- Published: May. 08, 2025
- Modified: May. 08, 2025
-
7.5
CVSS31CVE-2025-3419
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attacker... Read more
Affected Products : eventin- Published: May. 08, 2025
- Modified: May. 08, 2025
-
0.0
NONECVE-2025-37800
In the Linux kernel, the following vulnerability has been resolved: driver core: fix potential NULL pointer dereference in dev_uevent() If userspace reads "uevent" device attribute at the same time as another threads unbinds the device from its driver, ... Read more
Affected Products : linux_kernel- Published: May. 08, 2025
- Modified: May. 08, 2025