Aggregator
CVE-2025-1316 | Edimax IC-7100 IP Camera Requests os command injection (icsa-25-063-08)
9 months 1 week ago
A vulnerability, which was classified as very critical, was found in Edimax IC-7100 IP Camera. This affects an unknown part of the component Requests Handler. The manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-1316. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-1259 | Arista EOS up to 4.33.1 OpenConfig access control
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in Arista EOS up to 4.33.1. Affected by this issue is some unknown functionality of the component OpenConfig. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2025-1259. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-1260 | Arista EOS up to 4.33.1 OpenConfig access control
9 months 1 week ago
A vulnerability classified as critical was found in Arista EOS up to 4.33.1. Affected by this vulnerability is an unknown functionality of the component OpenConfig. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2025-1260. The attack can be launched remotely. There is no exploit available.
vuldb.com
RansomHub
9 months 1 week ago
cohenido
CVE-2025-26202 | DZS Router Web Interface Passphrase cross site scripting
9 months 1 week ago
A vulnerability classified as problematic has been found in DZS Router. Affected is an unknown function of the component Web Interface. The manipulation of the argument Passphrase leads to cross site scripting.
This vulnerability is traded as CVE-2025-26202. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-1969 | Amazon AWS Temporary Elevated Access Management for IAM Identity Center origin validation (GHSA-x9xv-r58p-qh86)
9 months 1 week ago
A vulnerability was found in Amazon AWS Temporary Elevated Access Management for IAM Identity Center up to 1.2.1. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to origin validation error.
The identification of this vulnerability is CVE-2025-1969. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DEF CON 32 – War Stories – Xiaomi The Money: Our Toronto Pwn2Own Exploit & BTS Story
9 months 1 week ago
Authors/Presenters: Ken Gannon, Ilyes Beghdadi
Our sincere appreciation to DEF CON, and the Authors/Presenters for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – War Stories – Xiaomi The Money: Our Toronto Pwn2Own Exploit & BTS Story appeared first on Security Boulevard.
Marc Handelman
CVE-2020-3122 | Cisco IronPort Security Management Appliance Web-based Management Interface access control
9 months 1 week ago
A vulnerability was found in Cisco IronPort Security Management Appliance and Secure Email and Web Manager. It has been declared as critical. This vulnerability affects unknown code of the component Web-based Management Interface. The manipulation leads to improper access controls.
This vulnerability was named CVE-2020-3122. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2019-1815 | Cisco Meraki MX67/Meraki MX68 information disclosure
9 months 1 week ago
A vulnerability was found in Cisco Meraki MX67 and Meraki MX68. It has been classified as problematic. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2019-1815. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2015-9251 | Oracle WebLogic Server 12.1.3.0.0/12.2.1.3.0 jQuery cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability was found in Oracle WebLogic Server 12.1.3.0.0/12.2.1.3.0. It has been classified as critical. This affects an unknown part of the component jQuery. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2015-9251. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-9251 | Oracle Retail Allocation 15.0.2 jQuery cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability, which was classified as critical, was found in Oracle Retail Allocation 15.0.2. Affected is an unknown function of the component jQuery. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2015-9251. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-9251 | Oracle Retail Invoice Matching 15.0 jQuery cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability has been found in Oracle Retail Invoice Matching 15.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component jQuery. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2015-9251. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-9251 | Oracle OSS Support Tools 19.1 Remote Diagnostic Agent cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability was found in Oracle OSS Support Tools 19.1. It has been classified as critical. This affects an unknown part of the component Remote Diagnostic Agent. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2015-9251. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-9251 | Oracle Real-Time Scheduler 2.3.0 Mobile Platform cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in Oracle Real-Time Scheduler 2.3.0. Affected by this issue is some unknown functionality of the component Mobile Platform. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2015-9251. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-9251 | Oracle Utilities Mobile Workforce Management 2.3.0 Mobile Platform cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability, which was classified as critical, was found in Oracle Utilities Mobile Workforce Management 2.3.0. This affects an unknown part of the component Mobile Platform. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2015-9251. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-9251 | Oracle Financial Services Reconciliation Framework 8.0.5/8.0.6 User Interface cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability was found in Oracle Financial Services Reconciliation Framework 8.0.5/8.0.6 and classified as critical. This issue affects some unknown processing of the component User Interface. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2015-9251. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-9251 | Oracle Hospitality Reporting/Analytics 9.1.0 Report cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability was found in Oracle Hospitality Reporting and Analytics 9.1.0. It has been classified as critical. Affected is an unknown function of the component Report. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2015-9251. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-9251 | Oracle Fusion Middleware MapViewer 12.2.1.3.0 Install cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability classified as critical was found in Oracle Fusion Middleware MapViewer 12.2.1.3.0. This vulnerability affects unknown code of the component Install. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2015-9251. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-9251 | Oracle JDeveloper 11.1.1.9.0/12.1.3.0.0/12.2.1.3.0 ADF Faces cross site scripting (Nessus ID 219433 / BID-105658)
9 months 1 week ago
A vulnerability, which was classified as critical, has been found in Oracle JDeveloper 11.1.1.9.0/12.1.3.0.0/12.2.1.3.0. This issue affects some unknown processing of the component ADF Faces. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2015-9251. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com