Latest CVE Feed
-
4.8
MEDIUMCVE-2025-4661
A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the disclosure of sensitive information. Note: Admin level privileg... Read more
Affected Products : fabric_operating_system- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
4.8
MEDIUMCVE-2025-48886
Hydra is a layer-two scalability solution for Cardano. Prior to version 0.22.0, the process assumes L1 event finality and does not consider failed transactions. Currently, Cardano L1 is monitored for certain events which are necessary for state progressio... Read more
Affected Products :- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-24287
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.... Read more
Affected Products :- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2025-23172
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP req... Read more
Affected Products : versa_director- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Server-Side Request Forgery
-
7.2
HIGHCVE-2025-23171
The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allow file uploads but uploads still succeed. In addition, the... Read more
Affected Products : versa_director- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2024-45208
The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availability (HA) information using a shared password. Affected versi... Read more
Affected Products : versa_director- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Misconfiguration
-
5.0
MEDIUMCVE-2025-6240
Improper Input Validation vulnerability in Profisee on Windows (filesystem modules) allows Path Traversal after authentication to the Profisee system.This issue affects Profisee: from 2020R1 before 2024R2.... Read more
Affected Products :- Published: Jun. 18, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
8.6
HIGHCVE-2025-20271
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an a... Read more
Affected Products :- Published: Jun. 18, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-23169
The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to ... Read more
Affected Products : versa_director- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.7
MEDIUMCVE-2025-23170
The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user ... Read more
Affected Products : versa_director- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-23173
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposure introduces sign... Read more
Affected Products : versa_director- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-24288
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes... Read more
Affected Products : versa_director- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-24291
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an att... Read more
Affected Products : versa_director- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-50183
OpenList Frontend is a UI component for OpenList. Prior to version 4.0.0-rc.4, a vulnerability exists in the file preview/browsing feature of the application, where files with a .py extension that contain JavaScript code wrapped in <script> tags may be in... Read more
Affected Products :- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.1
CRITICALCVE-2025-52467
pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to commit 8eb3567, the pgai repository was vulnerable to an attack allowing the exfiltration of all secrets used in one workflow. In partic... Read more
Affected Products :- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Information Disclosure
-
6.4
MEDIUMCVE-2025-6201
The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's conversion-pixel in all versions up to, and including, 1.49.0 due to insuff... Read more
Affected Products :- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
4.9
MEDIUMCVE-2025-5524
The OceanWP theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Select HTML tag in all versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers... Read more
Affected Products :- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4738
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yirmibes Software MY ERP allows SQL Injection.This issue affects MY ERP: before 1.170.... Read more
Affected Products :- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-49014
jq is a command-line JSON processor. In version 1.8.0 a heap use after free vulnerability exists within the function f_strflocaltime of /src/builtin.c. This issue has been patched in commit 499c91b, no known fix version exists at time of publication.... Read more
Affected Products : jq- Published: Jun. 19, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-49972
Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy allows Cross Site Request Forgery. This issue affects TM Replace Howdy: from n/a through 1.4.2.... Read more
Affected Products :- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Cross-Site Request Forgery