A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N and SNC-RX570N up to 1.30. This affects an unknown part of the component Administrative Interface. The manipulation leads to use of default credentials.
This vulnerability is uniquely identified as CVE-2025-5124. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
It is recommended to change the configuration settings.
The vendor was contacted early about this issue. They confirmed the existence but pointed out that they "have published the 'Hardening Guide' on the Web from July 2018 to January 2025 and have thoroughly informed customers of the recommendation to change their initial passwords".
A vulnerability, which was classified as problematic, has been found in XStream up to 1.4.9. Affected by this issue is the function xstream.fromXML. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2017-7957. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in IBM Notes and classified as problematic. Affected by this vulnerability is an unknown functionality of the component XStream. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2017-7957. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as critical, was found in Xstream up to 1.4.13. Affected is an unknown function of the component Security Framework. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2020-26217. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in XStream up to 1.4.14. Affected is an unknown function. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2020-26259. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in XStream up to 1.4.15. Affected by this issue is some unknown functionality. The manipulation leads to denial of service.
This vulnerability is handled as CVE-2021-21341. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in XStream up to 1.4.15. This affects an unknown part. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2021-21342. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in XStream up to 1.4.15. Affected is an unknown function. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2021-21351. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Oracle Banking Platform 2.4.0/2.7.1/2.9.0. This issue affects some unknown processing of the component Collections. The manipulation leads to os command injection.
The identification of this vulnerability is CVE-2020-26217. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Oracle BAM (Business Activity Monitoring) 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component General. The manipulation leads to os command injection.
This vulnerability is known as CVE-2020-26217. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle Endeca Information Discovery Studio 3.2.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component Studio. The manipulation leads to os command injection.
This vulnerability is handled as CVE-2020-26217. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in XStream up to 1.4.16. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2021-29505. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle Enterprise Manager Ops Center 12.4.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component XStream. The manipulation leads to code injection.
This vulnerability is known as CVE-2021-29505. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Oracle Utilities Framework up to 4.3.0.3.0 and classified as critical. This issue affects some unknown processing of the component UI/Batch/XAI. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2016-3674. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in XStream up to 1.4.8. It has been classified as critical. Affected is an unknown function of the component Dom4JDriver/DomDriver/JDomDriver/JDom2Driver/SjsxpDriver/StandardStaxDriver/WstxDrive. The manipulation as part of XML Document leads to information disclosure.
This vulnerability is traded as CVE-2016-3674. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in IBM Lotus Notes up to 9.0.1.6. Affected is an unknown function. The manipulation as part of XML Document leads to information disclosure.
This vulnerability is traded as CVE-2016-3674. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
60 packages have been discovered in the NPM index that attempt to collect sensitive host and network data and send it to a Discord webhook controlled by the threat actor. [...]
A vulnerability was found in Page Builder Plugin up to 2.0.0 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument login_url leads to cross site scripting.
This vulnerability is handled as CVE-2025-4223. The attack may be launched remotely. There is no exploit available.