Aggregator
CVE-2025-20269 | Cisco Evolved Programmable Network Manager Web-based Management Interface file inclusion (cisco-sa-pi-epnm-TET4GxBX)
9 months 1 week ago
A vulnerability categorized as problematic has been discovered in Cisco Evolved Programmable Network Manager and Prime Infrastructure. This impacts an unknown function of the component Web-based Management Interface. Such manipulation leads to file inclusion.
This vulnerability is documented as CVE-2025-20269. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-28041 | michaelliao itranswarp up to 2.19 doFilter access control (Issue 73 / EUVD-2025-25346)
9 months 1 week ago
A vulnerability marked as critical has been reported in michaelliao itranswarp up to 2.19. This issue affects the function doFilter. This manipulation causes improper access controls.
This vulnerability appears as CVE-2025-28041. The attacker needs to be present on the local network. There is no available exploit.
vuldb.com
CVE-2025-9680 | O2OA up to 10.0-410 Personal Profile Page page cross site scripting (Issue 176 / EUVD-2025-26261)
9 months 1 week ago
A vulnerability has been found in O2OA up to 10.0-410 and classified as problematic. This impacts an unknown function of the file /x_portal_assemble_designer/jaxrs/page of the component Personal Profile Page. Performing manipulation results in cross site scripting.
This vulnerability is identified as CVE-2025-9680. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
vuldb.com
CVE-2025-9695 | GalleryVault Gallery Vault App up to 4.5.2 on Android com.thinkyeah.galleryvault AndroidManifest.xml improper export of android application components (EUVD-2025-26275)
9 months 1 week ago
A vulnerability has been found in GalleryVault Gallery Vault App up to 4.5.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.thinkyeah.galleryvault. The manipulation leads to improper export of android application components.
This vulnerability is referenced as CVE-2025-9695. The attack can only be performed from a local environment. Furthermore, an exploit is available.
vuldb.com
CVE-2025-9681 | O2OA up to 10.0-410 Personal Profile Page agent cross site scripting (177/178)
9 months 1 week ago
A vulnerability was found in O2OA up to 10.0-410 and classified as problematic. Affected is an unknown function of the file /x_program_center/jaxrs/agent of the component Personal Profile Page. Executing manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2025-9681. The attack can be launched remotely. Moreover, an exploit is present.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
vuldb.com
CVE-2025-9682 | O2OA up to 10.0-410 Personal Profile Page appdict cross site scripting (Issue 179)
9 months 1 week ago
A vulnerability was found in O2OA up to 10.0-410. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the file /x_cms_assemble_control/jaxrs/design/appdict of the component Personal Profile Page. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2025-9682. The attack may be initiated remotely. In addition, an exploit is available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
vuldb.com
CVE-2025-9683 | O2OA up to 10.0-410 Personal Profile Page form cross site scripting (Issue 180)
9 months 1 week ago
A vulnerability was found in O2OA up to 10.0-410. It has been declared as problematic. Affected by this issue is some unknown functionality of the file /x_cms_assemble_control/jaxrs/form of the component Personal Profile Page. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2025-9683. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor replied in the GitHub issue (translated from simplified Chinese): "This issue will be fixed in the new version."
vuldb.com
CVE-2025-9694 | Campcodes Advanced Online Voting System 1.0 /admin/login.php Username sql injection (EUVD-2025-26273)
9 months 1 week ago
A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. Executing manipulation of the argument Username can lead to sql injection.
The identification of this vulnerability is CVE-2025-9694. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-38742 | Dell iDRAC Service Module up to 6.0.3.0 permission assignment (dsa-2025-311 / EUVD-2025-25485)
9 months 1 week ago
A vulnerability was found in Dell iDRAC Service Module up to 6.0.3.0. It has been declared as problematic. Affected by this issue is some unknown functionality. The manipulation results in incorrect permission assignment.
This vulnerability is known as CVE-2025-38742. Attacking locally is a requirement. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-57789 | Commvault CommCell up to 11.32.101/11.36.59 Administrator Login storing passwords in a recoverable format (Nessus ID 253649 / WID-SEC-2025-1867)
9 months 1 week ago
A vulnerability has been found in Commvault CommCell up to 11.32.101/11.36.59 and classified as problematic. The impacted element is an unknown function of the component Administrator Login Handler. This manipulation causes storing passwords in a recoverable format.
This vulnerability is handled as CVE-2025-57789. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-57790 | Commvault CommCell up to 11.32.101/11.36.59 absolute path traversal (Nessus ID 253649 / WID-SEC-2025-1867)
9 months 1 week ago
A vulnerability was found in Commvault CommCell up to 11.32.101/11.36.59 and classified as very critical. This affects an unknown function. Such manipulation leads to absolute path traversal.
This vulnerability is uniquely identified as CVE-2025-57790. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-57791 | Commvault CommCell up to 11.32.101/11.36.59 argument injection (Nessus ID 253649 / WID-SEC-2025-1867)
9 months 1 week ago
A vulnerability was found in Commvault CommCell up to 11.32.101/11.36.59. It has been classified as critical. This impacts an unknown function. Performing manipulation results in argument injection.
This vulnerability was named CVE-2025-57791. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
超越高通和博通:苹果内部芯片接管iPhone连接
9 months 1 week ago
安全客
Chinese APT Hits Philippine Military Firm with New EggStreme Fileless Malware
9 months 1 week ago
Bitdefender uncovers EggStreme, a fileless malware by a China-based APT targeting the Philippine military and APAC organisations. Cybersecurity…
Waqas
英伟达最新收购:这家AI编程初创公司将重塑开发格局
9 months 1 week ago
安全客
西门子SIMATIC虚拟化即服务平台曝严重漏洞(CVE-2025-40804):网络共享资源无需认证即可访问
9 months 1 week ago
安全客
Техобслуживание или прикрытие? Nemo Protocol потеряла $2,4 млн из-за хакерской атаки
9 months 1 week ago
Платформа приостановила работу после кибератаки.
Sophos修复AP6系列无线接入点严重认证绕过漏洞(CVE-2025-10159)
9 months 1 week ago
安全客
Hiawatha Web服务器曝严重漏洞:可导致身份认证绕过与远程代码执行
9 months 1 week ago
安全客