Aggregator
CVE-2024-6156 | Canonical LXD up to 5.21.1 PKI Mode certificate validation (GHSA-4c49-9fpc-hc3v)
5 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Canonical LXD up to 5.21.1. Affected is an unknown function of the component PKI Mode. The manipulation leads to improper certificate validation.
This vulnerability is traded as CVE-2024-6156. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-37000 | Huawei HarmonyOS 2.0 credentials management
5 months 3 weeks ago
A vulnerability was found in Huawei HarmonyOS 2.0. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to credentials management.
The identification of this vulnerability is CVE-2021-37000. The attack needs to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-21547 | Oracle Hospitality OPERA 5 5.6.19.20/5.6.25.8/5.6.26.6/5.6.27.1 Opera Servlet improper authentication
5 months 3 weeks ago
A vulnerability classified as very critical was found in Oracle Hospitality OPERA 5 5.6.19.20/5.6.25.8/5.6.26.6/5.6.27.1. This vulnerability affects unknown code of the component Opera Servlet. The manipulation leads to improper authentication.
This vulnerability was named CVE-2025-21547. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21532 | Oracle Analytics Desktop up to 8.0.x Install default permission
5 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Oracle Analytics Desktop up to 8.0.x. Affected is an unknown function of the component Install. The manipulation leads to incorrect default permissions.
This vulnerability is traded as CVE-2025-21532. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57360 | GNU Binutils 2.43 access control (Nessus ID 216857)
5 months 3 weeks ago
A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2024-57360. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-57019 | TOTOLINK X5000R 9.1.0cu.2350_B20230313 setVpnAccountCfg limit os command injection
5 months 3 weeks ago
A vulnerability classified as critical has been found in TOTOLINK X5000R 9.1.0cu.2350_B20230313. Affected is the function setVpnAccountCfg. The manipulation of the argument limit leads to os command injection.
This vulnerability is traded as CVE-2024-57019. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
Automox Demonstrates IT and Security Impact With Launch of Precision Analytics
5 months 3 weeks ago
CVE-2025-24799 | GLPI up to 10.0.17 Inventory Endpoint sql injection (GHSA-jv89-g7f7-jwfg)
5 months 3 weeks ago
A vulnerability classified as critical has been found in GLPI up to 10.0.17. This affects an unknown part of the component Inventory Endpoint. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-24799. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21619 | GLPI up to 10.0.17 sql injection (GHSA-pcmc-xv3g-hjxv)
5 months 3 weeks ago
A vulnerability was found in GLPI up to 10.0.17. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2025-21619. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30138 | G-Net Dashcam BB GONX Setting improper authorization
5 months 3 weeks ago
A vulnerability was found in G-Net Dashcam BB GONX. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Setting Handler. The manipulation leads to improper authorization.
This vulnerability is known as CVE-2025-30138. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
Fujifilm Signs Strategic Collaboration Agreement With Amazon Web Services
5 months 3 weeks ago
News alert: SquareX’s “Year of Browser Bugs” project exposes critical cybersecurity blind spots
5 months 3 weeks ago
Palo Alto, Calif., Mar. 18, 2025, CyberNewswire — SquareX, a pioneer in Browser Detection and Response (BDR) space, announced the launch of the “Year of Browser Bugs” (YOBB) project today, a year-long initiative to draw attention to the lack … (more…)
The post News alert: SquareX’s “Year of Browser Bugs” project exposes critical cybersecurity blind spots first appeared on The Last Watchdog.
The post News alert: SquareX’s “Year of Browser Bugs” project exposes critical cybersecurity blind spots appeared first on Security Boulevard.
cybernewswire
CVE-2025-29790 | Contao CMS up to 4.13.53/5.3.29/5.5.5 SVG File cross site scripting (GHSA-vqqr-fgmh-f626)
5 months 3 weeks ago
A vulnerability was found in Contao CMS up to 4.13.53/5.3.29/5.5.5. It has been classified as problematic. Affected is an unknown function of the component SVG File Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-29790. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30140 | G-Net Dashcam BB GONX Domain Name origin validation
5 months 3 weeks ago
A vulnerability was found in G-Net Dashcam BB GONX and classified as problematic. This issue affects some unknown processing of the component Domain Name Handler. The manipulation leads to origin validation error.
The identification of this vulnerability is CVE-2025-30140. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2025-29907 | parallax jsPDF up to 3.0.0 addImage resource consumption (GHSA-w532-jxjh-hjhj)
5 months 3 weeks ago
A vulnerability has been found in parallax jsPDF up to 3.0.0 and classified as problematic. This vulnerability affects the function addImage. The manipulation leads to resource consumption.
This vulnerability was named CVE-2025-29907. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-30139 | G-Net Dashcam BB GONX SSID default credentials
5 months 3 weeks ago
A vulnerability, which was classified as critical, was found in G-Net Dashcam BB GONX. This affects an unknown part of the component SSID Handler. The manipulation leads to use of default credentials.
This vulnerability is uniquely identified as CVE-2025-30139. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2025-30142 | G-Net Dashcam BB GONX Pairing improper authentication
5 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in G-Net Dashcam BB GONX. Affected by this issue is some unknown functionality of the component Pairing Handler. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2025-30142. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2025-30137 | G-Net GNet App 2.6.2 on Android API Endpoint hard-coded credentials
5 months 3 weeks ago
A vulnerability classified as critical was found in G-Net GNet App 2.6.2 on Android. Affected by this vulnerability is an unknown functionality of the component API Endpoint. The manipulation leads to hard-coded credentials.
This vulnerability is known as CVE-2025-30137. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2025-27080 | HPE AOS-CX up to 10.10.1140/10.13.1070/10.14.1030/10.15.1000 Command Line Interface improper authentication
5 months 3 weeks ago
A vulnerability classified as problematic has been found in HPE AOS-CX up to 10.10.1140/10.13.1070/10.14.1030/10.15.1000. Affected is an unknown function of the component Command Line Interface. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-27080. Local access is required to approach this attack. There is no exploit available.
vuldb.com