Latest CVE Feed
-
7.5
HIGHCVE-2025-32986
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Sensitive File Accessible Without Proper Authentication to an endpoint.... Read more
Affected Products : ngeniusone- Published: Apr. 25, 2025
- Modified: May. 27, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-32985
NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.... Read more
Affected Products : ngeniusone- Published: Apr. 25, 2025
- Modified: May. 27, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-32984
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.... Read more
Affected Products : ngeniusone- Published: Apr. 25, 2025
- Modified: May. 27, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-32983
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.... Read more
Affected Products : ngeniusone- Published: Apr. 25, 2025
- Modified: May. 27, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2025-32982
NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.... Read more
Affected Products : ngeniusone- Published: Apr. 25, 2025
- Modified: May. 27, 2025
- Vuln Type: Authorization
-
7.1
HIGHCVE-2025-32981
NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.... Read more
Affected Products : ngeniusone- Published: Apr. 25, 2025
- Modified: May. 27, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-32980
NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration.... Read more
Affected Products :- Published: Apr. 25, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-32979
NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.... Read more
Affected Products : ngeniusone- Published: Apr. 25, 2025
- Modified: May. 27, 2025
- Vuln Type: Misconfiguration
-
7.0
HIGHCVE-2025-28128
An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.... Read more
Affected Products : telecom_online_account_system- Published: Apr. 25, 2025
- Modified: May. 12, 2025
- Vuln Type: Authentication
-
8.1
HIGHCVE-2025-3935
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It is important to n... Read more
Affected Products : screenconnect- Actively Exploited
- Published: Apr. 25, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-30152
HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain access to sensitive information, modify data, or other impacts.... Read more
Affected Products : hcl_sx- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cryptography
-
9.8
CRITICALCVE-2025-25775
Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tiket/cekorder.... Read more
Affected Products : bus_ticket_booking_system- Published: Apr. 25, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3928
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.... Read more
- Actively Exploited
- Published: Apr. 25, 2025
- Modified: May. 28, 2025
- Vuln Type: Authentication
-
5.1
MEDIUMCVE-2025-2070
An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user.... Read more
Affected Products : filez_client- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Path Traversal
-
5.1
MEDIUMCVE-2025-2069
A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.... Read more
Affected Products : filez_client- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-2068
An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user.... Read more
Affected Products : filez_client- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2024-56156
Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lea... Read more
Affected Products : halo- Published: Apr. 25, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-46618
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab... Read more
Affected Products : teamcity- Published: Apr. 25, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-46433
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible... Read more
Affected Products : teamcity- Published: Apr. 25, 2025
- Modified: May. 16, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2025-46432
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs... Read more
Affected Products : teamcity- Published: Apr. 25, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure