Latest CVE Feed
-
7.0
HIGHCVE-2025-43887
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
4.4
MEDIUMCVE-2025-43886
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacke... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-43885
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially explo... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
8.2
HIGHCVE-2025-43884
Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially expl... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
7.8
HIGHCVE-2025-43725
Dell PowerProtect Data Manager, Generic Application Agent, version(s) 19.19 and 19.20, contain(s) an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code exe... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-29592
oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Path Traversal
-
7.4
HIGHCVE-2025-20340
A vulnerability in the Address Resolution Protocol (ARP) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a broadcast storm, leading to a denial of service (DoS) condition on an affected device. ... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Denial of Service
-
6.0
MEDIUMCVE-2025-20248
A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability,... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-20159
A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass configured ACLs for the SSH, NetConf, and gRPC features. This vulnerability exis... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Misconfiguration
-
0.0
NACVE-2025-56578
An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authentication mechanisms... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
0.0
NACVE-2025-56466
Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Information Disclosure
-
8.8
HIGHCVE-2025-56413
OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation parameter to the /api/v2/hosts/ssh/operate endpoint.... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-56407
A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/mysql.php. The manipulation of the argument sql leads to sql injection. The attack can be ... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-56406
An issue was discovered in mcp-neo4j 0.3.0 allowing attackers to gain sensitive information or execute arbitrary commands via the SSE service.... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-56405
An issue was discovered in litmusautomation litmus-mcp-server thru 0.0.1 allowing unauthorized attackers to control the target's MCP service through the SSE protocol.... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-56404
An issue was discovered in MariaDB MCP 0.1.0 allowing attackers to gain sensitive information via the SSE service as the SSE service lacks user validation.... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Information Disclosure
-
7.0
HIGHCVE-2025-10231
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions.... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-7718
The Resideo Plugin for Resideo - Real Estate WordPress Theme plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.5.4. This is due to the plugin not properly validating a user's identity p... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-10227
Missing Encryption of Sensitive Data (CWE-311) in the Object Archive component in AxxonSoft Axxon One before 2.0.8 on Windows and Linux allows a local attacker with access to exported storage or stolen physical drives to extract sensitive archive data in ... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-10226
Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via explo... Read more
Affected Products :- Published: Sep. 10, 2025
- Modified: Sep. 10, 2025
- Vuln Type: Supply Chain