Latest CVE Feed
-
4.3
MEDIUMCVE-2024-47055
SummaryThis advisory addresses a security vulnerability in Mautic related to the segment cloning functionality. This vulnerability allows any authenticated user to clone segments without proper authorization checks. Insecure Direct Object Reference (IDOR... Read more
Affected Products : mautic- Published: May. 28, 2025
- Modified: May. 29, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2025-5257
SummaryThis advisory addresses a security vulnerability in Mautic where unpublished page previews could be accessed by unauthenticated users and potentially indexed by search engines. This could lead to the unintended disclosure of draft content or sensit... Read more
Affected Products : mautic- Published: May. 28, 2025
- Modified: May. 29, 2025
- Vuln Type: Authorization
-
3.2
LOWCVE-2025-48931
The TeleMessage service through 2025-05-05 relies on MD5 for password hashing, which opens up various attack possibilities (including rainbow tables) with low computational effort.... Read more
Affected Products : telemessage- Published: May. 28, 2025
- Modified: May. 29, 2025
- Vuln Type: Cryptography
-
2.8
LOWCVE-2025-48930
The TeleMessage service through 2025-05-05 stores certain cleartext information in memory, even though memory content may be accessible to an adversary through various avenues.... Read more
Affected Products : telemessage- Published: May. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Information Disclosure
-
4.0
MEDIUMCVE-2025-48929
The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.... Read more
Affected Products : telemessage- Published: May. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
4.0
MEDIUMCVE-2025-48928
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.... Read more
Affected Products : telemessage- Actively Exploited
- Published: May. 28, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Information Disclosure
-
5.3
MEDIUMCVE-2025-48927
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.... Read more
Affected Products : telemessage- Actively Exploited
- Published: May. 28, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2025-48926
The admin panel in the TeleMessage service through 2025-05-05 allows attackers to discover usernames, e-mail addresses, passwords, and telephone numbers.... Read more
Affected Products : telemessage- Published: May. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-48925
The TeleMessage service through 2025-05-05 relies on the client side (e.g., the TM SGNL app) to do MD5 hashing, and then accepts the hash as the authentication credential.... Read more
Affected Products : telemessage- Published: May. 28, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-48746
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.... Read more
Affected Products : directory_manager- Published: May. 28, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Authentication
-
6.5
MEDIUMCVE-2025-36572
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vul... Read more
Affected Products : powerstoreos powerstore_500t powerstore_1000t powerstore_1200t powerstore_3200t powerstore_3000t powerstore_5200t powerstore_5000t powerstore_7000t powerstore_9000t +2 more products- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-32802
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecur... Read more
Affected Products : kea- Published: May. 28, 2025
- Modified: May. 29, 2025
- Vuln Type: Path Traversal
-
7.8
HIGHCVE-2025-32801
Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea ver... Read more
Affected Products : kea- Published: May. 28, 2025
- Modified: May. 29, 2025
- Vuln Type: Misconfiguration
-
5.1
MEDIUMCVE-2024-47056
SummaryThis advisory addresses a security vulnerability in Mautic where sensitive .env configuration files may be directly accessible via a web browser. This exposure could lead to the disclosure of sensitive information, including database credentials, A... Read more
Affected Products : mautic- Published: May. 28, 2025
- Modified: May. 29, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-45343
An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module in the goform/setmodules route.... Read more
- Published: May. 28, 2025
- Modified: Jun. 03, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-51453
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.... Read more
Affected Products : sterling_secure_proxy- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-38341
IBM Sterling Secure Proxy 6.0.0.0 through 6.0.3.1, 6.1.0.0 through 6.1.0.0, and 6.2.0.0 through 6.2.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.... Read more
Affected Products : sterling_secure_proxy- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-3357
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index value of a dynamically allocated array.... Read more
Affected Products : tivoli_monitoring- Published: May. 28, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
9.6
CRITICALCVE-2025-5277
aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run arbitrary commands on the host system.... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025
-
7.3
HIGHCVE-2025-4134
Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof or tamper with the update file via an unverified file write.... Read more
Affected Products :- Published: May. 28, 2025
- Modified: May. 28, 2025