Latest CVE Feed
-
8.6
HIGHCVE-2025-2732
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/wizard/getWifiNeighbour of the com... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-2731
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /api/wizard/getDualbandSync of... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-2730
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. It has been classified as critical. Affected is an unknown function of the file /api/wizard/getssidname of the component HTTP POST Requ... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-2729
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 and classified as critical. This issue affects some unknown processing of the file /api/wizard/networkSetup of the component HTTP POST R... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-2728
A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vulnerability affects unknown code of the file /api/wizard/getNetworkConf. The manipulation leads to command injection. The attack needs t... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-2727
A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unknown part of the file /api/wizard/getNetworkStatus of the component HTTP POST Request Handler. The manipulation leads to command injectio... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-2726
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this issue is some unknown functionality of the file /api/esps of the component HTT... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
8.6
HIGHCVE-2025-2725
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014. Affected by this vulnerability is an unknown functionality of the file /api/login/auth of the component HTTP POS... Read more
Affected Products :- Published: Mar. 25, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-2717
A vulnerability, which was classified as critical, has been found in D-Link DIR-823X 240126/240802. This issue affects the function sub_41710C of the file /goform/diag_nslookup of the component HTTP POST Request Handler. The manipulation of the argument t... Read more
- Published: Mar. 25, 2025
- Modified: May. 21, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-24514
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-... Read more
Affected Products : ingress-nginx- Published: Mar. 25, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-24513
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container... Read more
Affected Products : ingress-nginx- Published: Mar. 25, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-1974
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Se... Read more
Affected Products : ingress-nginx- Published: Mar. 25, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-1098
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execut... Read more
Affected Products : ingress-nginx- Published: Mar. 25, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-1097
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the... Read more
Affected Products : ingress-nginx- Published: Mar. 25, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Misconfiguration
-
5.1
MEDIUMCVE-2025-2716
A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unknown code of the component Samba Path Handler. The manipulation leads to path traversal. The attack can be initiated remotely. The expl... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
5.1
MEDIUMCVE-2025-2715
A vulnerability classified as problematic has been found in timschofield webERP up to 5.0.0.rc+13. This affects an unknown part of the file ConfirmDispatch_Invoice.php of the component Confirm Dispatch and Invoice Page. The manipulation of the argument Na... Read more
Affected Products :- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2025-2714
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /extensions/realestate/index.php/agents/agent-register/addagent. The manipulation of the argume... Read more
Affected Products : jux_real_estate- Published: Mar. 24, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-2712
A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /help/top.jsp. The manipulation of the argument langcode leads to cross site scripting. The a... Read more
Affected Products : ufida_erp-nc- Published: Mar. 24, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Cross-Site Scripting
-
9.9
CRITICALCVE-2025-26512
SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user on a remote system where a SnapCenter plug-in has been installed.... Read more
Affected Products : snapcenter- Published: Mar. 24, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2025-2711
A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown function of the file /help/systop.jsp. The manipulation of the argument langcode leads to cross site scripting. It is possible to launch th... Read more
Affected Products : ufida_erp-nc- Published: Mar. 24, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cross-Site Scripting