Latest CVE Feed
-
6.1
MEDIUMCVE-2025-20179
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-b... Read more
- Published: Feb. 05, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Cross-Site Scripting
-
7.7
HIGHCVE-2025-20176
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP r... Read more
- Published: Feb. 05, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-20175
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP r... Read more
- Published: Feb. 05, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-20174
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP r... Read more
- Published: Feb. 05, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-20173
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP r... Read more
- Published: Feb. 05, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-20172
A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error hand... Read more
- Published: Feb. 05, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-20171
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP r... Read more
- Published: Feb. 05, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-20170
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP r... Read more
- Published: Feb. 05, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
7.7
HIGHCVE-2025-20169
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP r... Read more
- Published: Feb. 05, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Denial of Service
-
9.1
CRITICALCVE-2025-20125
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorizatio... Read more
Affected Products : identity_services_engine- Published: Feb. 05, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authorization
-
9.9
CRITICALCVE-2025-20124
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the a... Read more
Affected Products : identity_services_engine- Published: Feb. 05, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
5.5
MEDIUMCVE-2024-42207
HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim's session ID from their authenticated session.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Authentication
-
8.7
HIGHCVE-2024-39564
This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path at... Read more
- Published: Feb. 05, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Memory Corruption
-
5.8
MEDIUMCVE-2025-0858
A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.... Read more
Affected Products :- Published: Feb. 05, 2025
- Modified: Mar. 27, 2025
- Vuln Type: Path Traversal
-
6.6
MEDIUMCVE-2025-21117
Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.... Read more
Affected Products : avamar_server- Published: Feb. 05, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Authentication
-
3.5
LOWCVE-2024-9097
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.... Read more
Affected Products : manageengine_endpoint_central- Published: Feb. 05, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-2878
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by craftin... Read more
Affected Products : gitlab- Published: Feb. 05, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Denial of Service
-
6.4
MEDIUMCVE-2024-52365
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed... Read more
Affected Products : cloud_pak_for_business_automation- Published: Feb. 05, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2024-52364
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitr... Read more
Affected Products : cloud_pak_for_business_automation- Published: Feb. 05, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-49348
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts. The fact that tasks of type co... Read more
Affected Products : cloud_pak_for_business_automation- Published: Feb. 05, 2025
- Modified: Aug. 12, 2025