Aggregator
CVE-2010-2245 | Apache Wink up to 1.1.1 XML Document xml external entity reference (WID-SEC-2025-2154)
8 months 3 weeks ago
A vulnerability labeled as critical has been found in Apache Wink up to 1.1.1. This impacts an unknown function of the component XML Document Handler. The manipulation results in xml external entity reference.
This vulnerability is reported as CVE-2010-2245. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-41251 | VMware NSX/NSX-T/Cloud Foundation password recovery (EUVD-2025-31600 / WID-SEC-2025-2155)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in VMware NSX, NSX-T and Cloud Foundation. This affects an unknown function. This manipulation causes weak password recovery.
This vulnerability is tracked as CVE-2025-41251. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-41252 | VMware NSX/NSX-T/Cloud Foundation information exposure (WID-SEC-2025-2155)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in VMware NSX, NSX-T and Cloud Foundation. This impacts an unknown function. Such manipulation leads to information exposure through discrepancy.
This vulnerability is listed as CVE-2025-41252. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2025-41250 | VMware vCenter SMTP Header command injection (EUVD-2025-31592 / WID-SEC-2025-2155)
8 months 3 weeks ago
A vulnerability has been found in VMware vCenter, Cloud Foundation, Telco Cloud Platform, Telco Cloud Infrastructure and vSphere Foundation and classified as critical. Affected is an unknown function of the component SMTP Header Handler. Performing manipulation results in command injection.
This vulnerability is cataloged as CVE-2025-41250. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
Weekly Report: Cisco ASAおよびFTDにおける複数の脆弱性(CVE-2025-20333、CVE-2025-20362)に関する注意喚起
8 months 3 weeks ago
Cisco Adaptive Security Appliance(ASA)およびFirewall Threat Defense(FTD)には、複数の脆弱性があります。これらの脆弱性の悪用を開発元は確認しているとのことです。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。
(图作者 | @Aoemax)
8 months 3 weeks ago
(图作者 | @Aoemax)
(图作者 | @Aoemax)
8 months 3 weeks ago
当前环境出现异常提示,需完成验证后才能继续访问。
10.1国庆节 | 山河峥嵘,家国同梦,祝福祖国76周年华诞!
8 months 3 weeks ago
工程中心祝您国庆快乐!
威努特国庆&中秋假期业务保障通知
8 months 3 weeks ago
双节同庆,安心守护~
CVE-2025-6517 | Dromara MaxKey up to 4.1.7 Meta URL SAML20DetailsController.java add post server-side request forgery (EUVD-2025-18913)
8 months 3 weeks ago
A vulnerability categorized as critical has been discovered in Dromara MaxKey up to 4.1.7. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\apps\contorller\SAML20DetailsController.java of the component Meta URL Handler. Executing manipulation of the argument post can lead to server-side request forgery.
This vulnerability is handled as CVE-2025-6517. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-41404 | iroha Soft iroha Board up to 0.10.12 direct request
8 months 3 weeks ago
A vulnerability was found in iroha Soft iroha Board up to 0.10.12. It has been classified as problematic. This issue affects some unknown processing. The manipulation leads to direct request.
This vulnerability is referenced as CVE-2025-41404. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2025-48497 | iroha Soft iroha Board up to 0.10.12 URL cross-site request forgery
8 months 3 weeks ago
A vulnerability was found in iroha Soft iroha Board up to 0.10.12. It has been rated as problematic. The affected element is an unknown function of the component URL Handler. This manipulation causes cross-site request forgery.
This vulnerability is tracked as CVE-2025-48497. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2025-27930 | Zoho ManageEngine Applications Manager up to 176600 File Monitor cross site scripting (EUVD-2025-22437)
8 months 3 weeks ago
A vulnerability marked as problematic has been reported in Zoho ManageEngine Applications Manager up to 176600. This vulnerability affects unknown code of the component File Monitor. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2025-27930. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-57730 | JetBrains IntelliJ IDEA up to 2025.1 Remote Development Feature cross site scripting (Nessus ID 253589 / WID-SEC-2025-1884)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in JetBrains IntelliJ IDEA up to 2025.1. Affected by this issue is some unknown functionality of the component Remote Development Feature. Executing manipulation can lead to basic cross site scripting.
This vulnerability appears as CVE-2025-57730. The attack requires local access. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2025-53500 | MassEditRegex Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki cross site scripting (EUVD-2025-19887)
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in MassEditRegex Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki. This affects an unknown function. Executing manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2025-53500. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-5692 | Lead Form Data Collection to CRM Plugin up to 3.1 on WordPress Setting doFieldAjaxAction improper authentication (EUVD-2025-19710)
8 months 3 weeks ago
A vulnerability classified as critical has been found in Lead Form Data Collection to CRM Plugin up to 3.1 on WordPress. Affected by this vulnerability is the function doFieldAjaxAction of the component Setting Handler. Performing manipulation results in improper authentication.
This vulnerability was named CVE-2025-5692. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2025-53494 | TwoColConflict Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki cross site scripting (EUVD-2025-19713)
8 months 3 weeks ago
A vulnerability identified as problematic has been detected in TwoColConflict Extension up to 1.39.12/1.42.6/1.43.1 on Mediawiki. This impacts an unknown function. Performing manipulation results in cross site scripting.
This vulnerability is identified as CVE-2025-53494. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-25012 | Elastic Kibana up to 8.17.2 File Upload prototype pollution (EUVD-2025-19084 / Nessus ID 232287)
8 months 3 weeks ago
A vulnerability categorized as critical has been discovered in Elastic Kibana up to 8.17.2. This affects an unknown function of the component File Upload Handler. Executing manipulation can lead to improperly controlled modification of object prototype attributes ('prototype pollution').
This vulnerability appears as CVE-2025-25012. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-6498 | HTACG tidy-html5 5.8.0 src/alloc.c defaultAlloc memory leak (Issue 1152 / EUVD-2025-18861)
8 months 3 weeks ago
A vulnerability classified as problematic has been found in HTACG tidy-html5 5.8.0. This vulnerability affects the function defaultAlloc of the file src/alloc.c. The manipulation leads to memory leak.
This vulnerability is listed as CVE-2025-6498. The attack must be carried out locally. In addition, an exploit is available.
vuldb.com