Latest CVE Feed
-
5.4
MEDIUMCVE-2021-1466
A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to cause a buffer overflow on an affected system, resulting in a denial of service (DoS) condition. The vulnerability is due to... Read more
Affected Products : catalyst_sd-wan_manager- Published: Nov. 15, 2024
- Modified: Aug. 04, 2025
-
5.3
MEDIUMCVE-2024-4067
The NPM package `micromatch` prior to 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payloa... Read more
Affected Products : micromatch- Published: May. 14, 2024
- Modified: Aug. 04, 2025
-
5.0
MEDIUMCVE-2021-1464
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of an affected system. This vulnerability exists because the ... Read more
Affected Products : catalyst_sd-wan_manager- Published: Nov. 15, 2024
- Modified: Aug. 04, 2025
-
4.3
MEDIUMCVE-2021-1465
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a directory traversal attack and obtain read access to sensitive files on an affected system. The vulnerabili... Read more
Affected Products : catalyst_sd-wan_manager- Published: Nov. 18, 2024
- Modified: Aug. 04, 2025
-
6.7
MEDIUMCVE-2021-1462
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to elevate privileges on an affected system. To exploit this vulnerability, an attacker would need to have a valid Administrator account on an af... Read more
Affected Products : catalyst_sd-wan_manager- Published: Nov. 18, 2024
- Modified: Aug. 04, 2025
-
7.8
HIGHCVE-2020-26074
A vulnerability in system file transfer functions of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to gain escalated privileges on the underlying operating system. The vulnerability is due to improper validation of path ... Read more
Affected Products : catalyst_sd-wan_manager- Published: Nov. 18, 2024
- Modified: Aug. 04, 2025
-
7.5
HIGHCVE-2020-26073
A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal charac... Read more
Affected Products : catalyst_sd-wan_manager- Published: Nov. 18, 2024
- Modified: Aug. 04, 2025
-
6.5
MEDIUMCVE-2025-20187
A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper valid... Read more
Affected Products : catalyst_sd-wan_manager- Published: May. 07, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Path Traversal
-
5.5
MEDIUMCVE-2025-20213
A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, local attacker to overwrite arbitrary files on the local file system of an affected device. To exploit this vulnerability, the attack... Read more
Affected Products : catalyst_sd-wan_manager- Published: May. 07, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-4068
The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, whic... Read more
- Published: May. 14, 2024
- Modified: Aug. 04, 2025
-
7.4
HIGHCVE-2024-25079
A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.... Read more
Affected Products : insydeh2o- Published: May. 15, 2024
- Modified: Aug. 04, 2025
-
5.5
MEDIUMCVE-2024-20394
A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the inability to handle unexpected input. An a... Read more
- Published: May. 15, 2024
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2024-33625
CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.... Read more
Affected Products : powerpanel- Published: May. 15, 2024
- Modified: Aug. 04, 2025
-
6.5
MEDIUMCVE-2020-26066
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML Exte... Read more
Affected Products : catalyst_sd-wan_manager- Published: Nov. 18, 2024
- Modified: Aug. 04, 2025
-
9.8
CRITICALCVE-2024-34025
CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.... Read more
Affected Products : powerpanel- Published: May. 15, 2024
- Modified: Aug. 04, 2025
-
7.5
HIGHCVE-2024-10382
There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction of arbitrary java classes. This can lead to arbitrary code execution when combined with specific Java des... Read more
- Published: Nov. 20, 2024
- Modified: Aug. 04, 2025
-
7.8
HIGHCVE-2025-2297
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile... Read more
Affected Products : privilege_management_for_windows- Published: Jul. 28, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-6250
Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any pr... Read more
Affected Products : privilege_management_for_windows- Published: Jul. 28, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2025-24853
A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki t... Read more
Affected Products : jspwiki- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-24854
A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWi... Read more
Affected Products : jspwiki- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Cross-Site Scripting