| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-56523 | Cri | 0.59 | 9.1 | 0.01 | May 12, 2025 | Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method. | ||
| CVE-2025-4559 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2025 | The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | ||
| CVE-2025-4558 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2025 | The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system. | ||
| CVE-2025-4557 | Cri | 0.59 | 9.1 | 0.01 | May 12, 2025 | The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system. | ||
| CVE-2025-4556 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2025 | The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | ||
| CVE-2025-4555 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2025 | The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking… | ||
| CVE-2025-46192 | Cri | 0.64 | 9.8 | 0.00 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter. | ||
| CVE-2025-46191 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and… | ||
| CVE-2025-46190 | Cri | 0.64 | 9.8 | 0.00 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter. | ||
| CVE-2025-46193 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php. | ||
| CVE-2025-46189 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter. | ||
| CVE-2025-46188 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php. | ||
| CVE-2025-45513 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter. | ||
| CVE-2025-28200 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address. | ||
| CVE-2025-45887 | Cri | 0.59 | 9.1 | 0.00 | May 9, 2025 | Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent. | ||
| CVE-2025-45885 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries. | ||
| CVE-2024-12442 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access. | ||
| CVE-2024-11861 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access. | ||
| CVE-2025-1087 | Cri | 0.54 | — | 0.01 | May 9, 2025 | Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to… | ||
| CVE-2025-4403 | Cri | 0.57 | 9.8 | 0.02 | May 9, 2025 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or… | ||
| CVE-2025-3605 | Cri | 0.67 | 9.8 | 0.07 | May 9, 2025 | The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email… | ||
| CVE-2025-37879 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read count then we would… | ||
| CVE-2025-2253 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3. This is due to the plugin not properly validating a verification code value prior to updating their password through the imic_reset_password_init()… | ||
| CVE-2024-11617 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'zetra_languageUpload' and 'zetra_fontsUpload' functions in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to… | ||
| CVE-2025-3463 | Cri | 0.61 | — | 0.01 | May 9, 2025 | "This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability in ASUS DriverHub may allow untrusted sources to affect system behavior via crafted HTTP requests. Refer to the 'Security Update… | ||
| CVE-2025-3714 | Cri | 0.64 | 9.8 | 0.02 | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device. | ||
| CVE-2025-3711 | Cri | 0.64 | 9.8 | 0.02 | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device. | ||
| CVE-2025-3710 | Cri | 0.64 | 9.8 | 0.02 | May 9, 2025 | The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device. | ||
| CVE-2025-3811 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the… | ||
| CVE-2025-3810 | Cri | 0.57 | 9.8 | 0.01 | May 9, 2025 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the… | ||
| CVE-2025-47733 | Cri | 0.59 | 9.1 | 0.02 | May 8, 2025 | Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network | ||
| CVE-2025-29972 | Cri | 0.65 | 9.9 | 0.04 | May 8, 2025 | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-29827 | Cri | 0.64 | 9.9 | 0.02 | May 8, 2025 | Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-29813 | Cri | 0.65 | 10.0 | 0.02 | May 8, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2023-31585 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2025 | Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php. | ||
| CVE-2025-45798 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2025 | A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter. | ||
| CVE-2025-45797 | Cri | 0.65 | 9.8 | 0.18 | May 8, 2025 | TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the NoticeUrl parameter in the setNoticeCfg interface of /lib/cste_modules/system.so. | ||
| CVE-2025-45790 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so. | ||
| CVE-2025-45789 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules. | ||
| CVE-2025-45788 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules. | ||
| CVE-2025-45787 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2025 | TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules. | ||
| CVE-2025-0505 | Cri | 0.65 | 10.0 | 0.01 | May 8, 2025 | On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under… | ||
| CVE-2024-12378 | Cri | 0.59 | 9.1 | 0.01 | May 8, 2025 | On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear. | ||
| CVE-2024-11186 | Cri | 0.65 | 10.0 | 0.01 | May 8, 2025 | On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact… | ||
| CVE-2025-26845 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2025 | An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script. | ||
| CVE-2025-45841 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2025 | TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function. | ||
| CVE-2025-26844 | Cri | 0.64 | 9.8 | 0.00 | May 8, 2025 | An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag. | ||
| CVE-2025-3476 | Cri | 0.61 | — | 0.00 | May 7, 2025 | Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4. | ||
| CVE-2025-46828 | Cri | 0.00 | 9.8 | 0.01 | May 7, 2025 | WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3.0 in the endpoint `/html/socio/sistema/get_socios.php`, specifically in the query parameter. This issue allows attackers to… | ||
| CVE-2025-20188 | Cri | 0.66 | 10.0 | 0.27 | May 7, 2025 | A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to… |
- risk 0.59cvss 9.1epss 0.01
Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by placing random data in the HTTP request body when using the HTTP GET method.
- risk 0.64cvss 9.8epss 0.01
The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
- risk 0.64cvss 9.8epss 0.01
The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
- risk 0.59cvss 9.1epss 0.01
The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access specific APIs and operate system functions. These functions include opening gates and restarting the system.
- risk 0.64cvss 9.8epss 0.01
The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
- risk 0.64cvss 9.8epss 0.01
The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access system functions. These functions include opening gates, viewing license plates and parking…
- risk 0.64cvss 9.8epss 0.00
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.
- risk 0.64cvss 9.8epss 0.01
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and…
- risk 0.64cvss 9.8epss 0.00
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.
- risk 0.64cvss 9.8epss 0.01
Tenda FH451 V1.0.0.9 has a stack overflow vulnerability in the function.P2pListFilter.
- risk 0.64cvss 9.8epss 0.01
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.
- risk 0.59cvss 9.1epss 0.00
Yifang CMS v2.0.2 is vulnerable to Server-Side Request Forgery (SSRF) in /api/file/getRemoteContent.
- risk 0.64cvss 9.8epss 0.01
PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.
- risk 0.64cvss 9.8epss 0.01
EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.
- risk 0.64cvss 9.8epss 0.01
EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.
- risk 0.54cvss —epss 0.01
Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to…
- risk 0.57cvss 9.8epss 0.02
The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or…
- risk 0.67cvss 9.8epss 0.07
The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email…
- risk 0.64cvss 9.8epss 0.01
In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read count then we would…
- risk 0.64cvss 9.8epss 0.01
The IMITHEMES Listing plugin is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3. This is due to the plugin not properly validating a verification code value prior to updating their password through the imic_reset_password_init()…
- risk 0.64cvss 9.8epss 0.01
The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'zetra_languageUpload' and 'zetra_fontsUpload' functions in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to…
- risk 0.61cvss —epss 0.01
"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability in ASUS DriverHub may allow untrusted sources to affect system behavior via crafted HTTP requests. Refer to the 'Security Update…
- risk 0.64cvss 9.8epss 0.02
The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.02
The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.02
The LCD KVM over IP Switch CL5708IM has a Stack-based Buffer Overflow vulnerability in firmware versions prior to v2.2.215, allowing unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.01
The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the…
- risk 0.57cvss 9.8epss 0.01
The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like password and email through the…
- risk 0.59cvss 9.1epss 0.02
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
- risk 0.65cvss 9.9epss 0.04
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
- risk 0.64cvss 9.9epss 0.02
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
- risk 0.65cvss 10.0epss 0.02
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Grocery-CMS-PHP-Restful-API v1.3 is vulnerable to File Upload via /admin/add-category.php.
- risk 0.64cvss 9.8epss 0.01
A command execution vulnerability exists in the TOTOLINK A950RG V4.1.2cu.5204_B20210112. The vulnerability is located in the setNoticeCfg interface within the /lib/cste_modules/system.so library, specifically in the processing of the IpTo parameter.
- risk 0.65cvss 9.8epss 0.18
TOTOlink A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the NoticeUrl parameter in the setNoticeCfg interface of /lib/cste_modules/system.so.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the priority parameter in the setMacQos interface of /lib/cste_modules/firewall.so.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3100R V5.9c.1527 is vulnerable to buffer overflow via the urlKeyword parameter in setParentalRules.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow via the comment parameter in setMacFilterRules.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK A3100R V5.9c.1527 is vulnerable to Buffer Overflow viathe comment parameter in setIpPortFilterRules.
- risk 0.65cvss 10.0epss 0.01
On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under…
- risk 0.59cvss 9.1epss 0.01
On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
- risk 0.65cvss 10.0epss 0.01
On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact…
- risk 0.64cvss 9.8epss 0.01
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.
- risk 0.64cvss 9.8epss 0.01
TOTOLINK NR1800X V9.1.0u.6681_B20230703 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.
- risk 0.64cvss 9.8epss 0.00
An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.
- risk 0.61cvss —epss 0.00
Incorrect Authorization vulnerability in OpenText™ Operations Bridge Manager. The vulnerability could allows privilege escalation by authenticated users.This issue affects Operations Bridge Manager: 2023.05, 23.4, 24.2, 24.4.
- risk 0.00cvss 9.8epss 0.01
WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3.0 in the endpoint `/html/socio/sistema/get_socios.php`, specifically in the query parameter. This issue allows attackers to…
- risk 0.66cvss 10.0epss 0.27
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to…