Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.5

    HIGH
    CVE-2024-45481

    An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may allow an authenticated local attacker to authenticate as another legitimate user.... Read more

    Affected Products : industrial_automation_aprol
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Authentication
  • 9.2

    CRITICAL
    CVE-2024-45480

    An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to read files from the local system.... Read more

    Affected Products : industrial_automation_aprol
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Injection
  • 8.5

    HIGH
    CVE-2024-10209

    An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read and alter the configuration of another engineering or runtime user.... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Authorization
  • 5.1

    MEDIUM
    CVE-2024-10208

    An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to insert malicious code which is then executed in the context of the user’s... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Cross-Site Scripting
  • 5.3

    MEDIUM
    CVE-2024-10207

    A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to force the web server to request arbitrary URLs.... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Server-Side Request Forgery
  • 6.9

    MEDIUM
    CVE-2024-10206

    A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs.... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Server-Side Request Forgery
  • 8.6

    HIGH
    CVE-2025-2732

    A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the com... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Apr. 11, 2025
    • Vuln Type: Injection
  • 8.6

    HIGH
    CVE-2025-2731

    A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Apr. 11, 2025
    • Vuln Type: Injection
  • 8.6

    HIGH
    CVE-2025-2730

    A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Requ... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Apr. 11, 2025
    • Vuln Type: Injection
  • 8.6

    HIGH
    CVE-2025-2729

    A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST R... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Apr. 11, 2025
    • Vuln Type: Injection
  • 8.6

    HIGH
    CVE-2025-2728

    A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack needs t... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Apr. 11, 2025
    • Vuln Type: Injection
  • 8.6

    HIGH
    CVE-2025-2727

    A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file /api/wizard/getNetworkStatus of the component HTTP POST Request Handler. The manipulation leads to command injectio... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Apr. 11, 2025
    • Vuln Type: Injection
  • 8.6

    HIGH
    CVE-2025-2726

    A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTT... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Apr. 11, 2025
    • Vuln Type: Injection
  • 8.6

    HIGH
    CVE-2025-2725

    A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POS... Read more

    Affected Products :
    • Published: Mar. 25, 2025
    • Modified: Apr. 11, 2025
    • Vuln Type: Injection
  • 7.2

    HIGH
    CVE-2025-2717

    A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of the component HTTP POST Request Handler. The manipulation of the argument t... Read more

    Affected Products : dir-823x_firmware dir-823x
    • Published: Mar. 25, 2025
    • Modified: May. 21, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-24514

    A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-... Read more

    Affected Products : ingress-nginx
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Authentication
  • 4.8

    MEDIUM
    CVE-2025-24513

    A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container... Read more

    Affected Products : ingress-nginx
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Path Traversal
  • 9.8

    CRITICAL
    CVE-2025-1974

    A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Se... Read more

    Affected Products : ingress-nginx
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Authentication
  • 8.8

    HIGH
    CVE-2025-1098

    A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execut... Read more

    Affected Products : ingress-nginx
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Injection
  • 8.8

    HIGH
    CVE-2025-1097

    A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the... Read more

    Affected Products : ingress-nginx
    • Published: Mar. 25, 2025
    • Modified: Mar. 27, 2025
    • Vuln Type: Misconfiguration
Showing 20 of 291736 Results