Aggregator
CVE-2025-36546 | F5 F5OS-A/F5OS-C Appliance Mode improper authentication (K000140574)
9 months ago
A vulnerability, which was classified as critical, was found in F5 F5OS-A and F5OS-C. This affects an unknown part of the component Appliance Mode. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2025-36546. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-36525 | F5 BIG-IP APM Traffic Management Microkernel buffer overflow (K000150598)
9 months ago
A vulnerability, which was classified as problematic, has been found in F5 BIG-IP APM. Affected by this issue is some unknown functionality of the component Traffic Management Microkernel. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2025-36525. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Tech Talk- AI Engine: A look at Transformative AI for Deep Insight into Anomalous Traffic
9 months ago
Graph-based anomaly detection transforms how network operators uncover threats and service issues by providing a deeper, relationship-driven understanding of all network activity traversing the eco-system. Unlike traditional methods that analyze isolated data points or rely on predefined rules, a graph-based approach leverages AI, ML, and graph theory to map and analyze the intricate relationships between […]
The post Tech Talk- AI Engine: A look at Transformative AI for Deep Insight into Anomalous Traffic appeared first on Security Boulevard.
psilva
CVE-2025-4127 | WP SEO Structured Data Schema Plugin up to 2.7.11 on WordPress Setting cross site scripting
9 months ago
A vulnerability classified as problematic was found in WP SEO Structured Data Schema Plugin up to 2.7.11 on WordPress. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-4127. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-3419 | Manager, Events Calendar, Tickets, Registrations Plugin proxy_image path traversal
9 months ago
A vulnerability classified as critical has been found in Manager, Events Calendar, Tickets, Registrations Plugin up to 4.0.26 on WordPress. Affected is the function proxy_image. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2025-3419. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
PowerSchool hacker now extorting individual school districts
9 months ago
PowerSchool is warning that the hacker behind its December cyberattack is now individually extorting schools, threatening to release the previously stolen student and teacher data if a ransom is not paid. [...]
Lawrence Abrams
CVE-2025-47203 | Dropbear SSH up to 2025.87 Hostname os command injection
9 months ago
A vulnerability was found in Dropbear SSH up to 2025.87. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument Hostname leads to os command injection.
The identification of this vulnerability is CVE-2025-47203. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-32820 | SonicWall SMA100 SSLVPN path traversal (SNWLID-2025-0011)
9 months ago
A vulnerability was found in SonicWall SMA100. It has been declared as critical. This vulnerability affects unknown code of the component SSLVPN. The manipulation leads to path traversal.
This vulnerability was named CVE-2025-32820. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-46824 | discourse-code-review Plugin on Discourse Link cross site scripting (GHSA-358v-cwvc-gxh5)
9 months ago
A vulnerability was found in discourse-code-review Plugin on Discourse. It has been classified as problematic. This affects an unknown part of the component Link Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-46824. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-32819 | SonicWall SMA100 SSLVPN file access (SNWLID-2025-0011)
9 months ago
A vulnerability was found in SonicWall SMA100 and classified as problematic. Affected by this issue is some unknown functionality of the component SSLVPN. The manipulation leads to files or directories accessible.
This vulnerability is handled as CVE-2025-32819. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-20213 | Cisco Catalyst SD-WAN Manager up to 20.15.2_LI_Images CLI os command injection (cisco-sa-sdwan-fileoverwrite-Uc9tXWH)
9 months ago
A vulnerability has been found in Cisco Catalyst SD-WAN Manager and classified as critical. Affected by this vulnerability is an unknown functionality of the component CLI. The manipulation leads to os command injection.
This vulnerability is known as CVE-2025-20213. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-46828 | LabRedesCefetRJ WeGIA up to 3.3.0 get_socios.php get_socios Query sql injection (GHSA-5qw5-q55h-6qg7)
9 months ago
A vulnerability, which was classified as critical, was found in LabRedesCefetRJ WeGIA up to 3.3.0. Affected is the function get_socios of the file /html/socio/sistema/get_socios.php. The manipulation of the argument Query leads to sql injection.
This vulnerability is traded as CVE-2025-46828. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-47423 | pwsdashboard Personal Weather Station Dashboard 12_lts /others/_test.php test path traversal
9 months ago
A vulnerability, which was classified as problematic, has been found in pwsdashboard Personal Weather Station Dashboard 12_lts. This issue affects some unknown processing of the file /others/_test.php. The manipulation of the argument test leads to path traversal: '../filedir'.
The identification of this vulnerability is CVE-2025-47423. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-20216 | Cisco Catalyst SD-WAN Manager up to 20.15.1_LI_Images Web Interface injection (cisco-sa-vmanage-html-inj-GxVtK6zj)
9 months ago
A vulnerability classified as problematic was found in Cisco Catalyst SD-WAN Manager. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to injection.
This vulnerability was named CVE-2025-20216. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-20223 | Cisco Catalyst Center access control (cisco-sa-catc-insec-acc-mtt8EhEb)
9 months ago
A vulnerability classified as critical has been found in Cisco Catalyst Center and Digital Network Architecture Center. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2025-20223. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-20214 | Cisco IOS XE up to 17.13.1a Access Control Module authorization (cisco-sa-netconf-nacm-bypass-TGZV9pmQ)
9 months ago
A vulnerability was found in Cisco IOS XE. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Access Control Module. The manipulation leads to authorization bypass.
This vulnerability is handled as CVE-2025-20214. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-20210 | Cisco Digital Network Architecture Center up to 2.3.7.7-VA Management API missing authentication (cisco-sa-dnac-api-nBPZcJCM)
9 months ago
A vulnerability was found in Cisco Digital Network Architecture Center. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Management API. The manipulation leads to missing authentication.
This vulnerability is known as CVE-2025-20210. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-20221 | Cisco IOS XE up to 17.16.1a Packet Filtering information disclosure (cisco-sa-snmp-bypass-HHUVujdn)
9 months ago
A vulnerability was found in Cisco IOS XE. It has been classified as problematic. Affected is an unknown function of the component Packet Filtering. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-20221. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Выбор Папы в XXI веке: реакция окислителя, углеводорода и серы — и никакой мистики
9 months ago
Как в Ватикане делают черный и белый дым без шанса на ошибку.