Latest CVE Feed
-
7.2
HIGHCVE-2025-20276
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, remote attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credential... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2025-20275
A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an unauthenticated attacker to execute arbitrary code on an affected device. This vulnerability is due to insecure deserializatio... Read more
Affected Products : unified_contact_center_express- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-20273
A vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management inte... Read more
Affected Products : unified_intelligent_contact_management_enterprise- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-20261
A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elev... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2025-20259
Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device. These vulnerabilities are due to improper access controls on f... Read more
- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-20163
A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices. This vulnerability is due to insufficient SSH host key validation. An... Read more
- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2025-20130
A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability... Read more
- Published: Jun. 04, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2025-20129
A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to impro... Read more
- Published: Jun. 04, 2025
- Modified: Aug. 01, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-5594
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknown code of the component SET Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The explo... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5593
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part of the component HOST Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The ex... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-29094
Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Marketing/Forms, Marketing/Offers and Content/Pages components.... Read more
Affected Products : content_management_system- Published: Jun. 04, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
8.2
HIGHCVE-2025-29093
File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images component.... Read more
Affected Products : content_management_system- Published: Jun. 04, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-23106
An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.... Read more
Affected Products : exynos_2200_firmware exynos_2200 exynos_2400_firmware exynos_2400 exynos_1480_firmware exynos_1480- Published: Jun. 04, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-23101
An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privilege escalation.... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-23096
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2025-23095
An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5592
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is some unknown functionality of the component PASSIVE Command Handler. The manipulation leads to buffer overflow. The attack may be laun... Read more
- Published: Jun. 04, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-48962
Sensitive information disclosure due to SSRF. The following products are affected: Acronis Cyber Protect 16 (Windows, Linux) before build 39938.... Read more
Affected Products : cyber_protect- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2025-48961
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39938.... Read more
Affected Products : cyber_protect- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
5.9
MEDIUMCVE-2025-48960
Weak server key used for TLS encryption. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938.... Read more
Affected Products : cyber_protect- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cryptography