CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2025-1976Mittel6.7
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
- CVE-2025-34028Kritisch10.0
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious JSP. This issue affects Command Center Innovation Release: 11.38.0 to 11.38.20. The vulnerability is fixed in 11.38.20 with SP38-CU20-433 and SP38-CU20-436 and also fixed in 11.38.25 with SP38-CU25-434 and SP38-CU25-438.
- CVE-2025-42599Kritisch9.8
Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.
- CVE-2025-32433Kritisch10.0
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.
- CVE-2025-31201Kritisch9.8
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.
- CVE-2025-31200Kritisch9.8
A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1.
- CVE-2024-58136Kritisch9.0
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
- CVE-2025-29824Hoch7.8
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
- CVE-2025-3248Kritisch9.8
Langflow-Versionen vor 1.3.0 sind anfällig für Code Injection im Endpunkt /api/v1/validate/code. Ein remote, nicht authentifizierter Angreifer kann präparierte HTTP-Requests senden, um beliebigen Code auszuführen.
- CVE-2025-31161Kritisch9.8
CrushFTP 10 vor 10.8.4 und 11 vor 11.3.1 ermöglicht eine Authentifizierungsumgehung und Übernahme des Kontos crushadmin (es sei denn, eine DMZ-Proxy-Instanz wird verwendet), wie im März und April 2025 in freier Wildbahn ausgenutzt, auch bekannt als „Unauthenticated HTTP(S) port access“. Im AWS4-HMAC-Autorisierungsverfahren (kompatibel mit S3) der HTTP-Komponente des FTP-Servers besteht eine Race Condition. Der Server überprüft zunächst die Existenz des Benutzers, indem er einen Aufruf an login_user_pass() ohne Passwortanforderung durchführt. Dadurch wird die Sitzung durch den HMAC-Verifizierungsprozess authentifiziert, und zwar bis zu dem Zeitpunkt, an dem der Server die Benutzerüberprüfung erneut durchführt. Die Schwachstelle kann weiter stabilisiert werden, wodurch die Notwendigkeit entfällt, eine Race Condition erfolgreich auszulösen, indem ein manipulierter AWS4-HMAC-Header gesendet wird. Indem nur der Benutzername und ein folgender Schrägstrich (/) angegeben werden, findet der Server erfolgreich einen Benutzernamen, was den erfolgreichen anypass-Authentifizierungsprozess auslöst, aber der Server findet den erwarteten SignedHeaders-Eintrag nicht, was zu einem Index-out-of-bounds-Fehler führt, der verhindert, dass der Code die Sitzungsbereinigung erreicht. Zusammen machen diese Probleme es trivial, sich als jeder bekannte oder erratbare Benutzer (z. B. crushadmin) zu authentifizieren, und können zu einer vollständigen Kompromittierung des Systems führen, indem ein administratives Konto erlangt wird.
- CVE-2025-30406Kritisch9.0
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to achieve remote code execution. NOTE: a CentreStack admin can manually delete the machineKey defined in portal\web.config.
- CVE-2025-22457Kritisch9.0
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
- CVE-2025-31125Mittel5.3
Vite ist ein Frontend-Tooling-Framework für JavaScript. Vite legt den Inhalt nicht erlaubter Dateien über ?inline&import oder ?raw?import offen. Betroffen sind nur Anwendungen, die den Vite-Entwicklungsserver ausdrücklich für das Netzwerk zugänglich machen (unter Verwendung von --host oder der Konfigurationsoption server.host). Diese Schwachstelle wurde in 6.2.4, 6.1.3, 6.0.13, 5.4.16 und 4.5.11 behoben.
- CVE-2025-2894Mittel6.6
Der Go1, auch bekannt als "The World's First Intelligence Bionic Quadruped Robot Companion of Consumer Level", enthält eine undokumentierte Backdoor, die dem Hersteller und jeder Person im Besitz des korrekten API-Keys die vollständige Fernsteuerung des betroffenen Robotikgeräts über den CloudSail-Fernzugriffsdienst ermöglichen kann.
- CVE-2025-2783Hoch8.3
Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High)
- CVE-2025-29635Hoch7.2
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.
- CVE-2025-2749Hoch7.2
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.
- CVE-2025-2747Kritisch9.8
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.
- CVE-2025-2746Kritisch9.8
An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.
- CVE-2025-30208Mittel5.3
Vite, ein Anbieter von Frontend-Entwicklungswerkzeugen, weist in den Versionen vor 6.2.3, 6.1.2, 6.0.12, 5.4.15 und 4.5.10 eine Schwachstelle auf. `@fs` verweigert den Zugriff auf Dateien außerhalb der Allow-Liste für die Auslieferung durch Vite. Das Hinzufügen von `?raw??` oder `?import&raw??` zur URL umgeht diese Einschränkung und gibt den Dateiinhalt zurück, wenn die Datei vorhanden ist. Dieser Umgehungsweg besteht, weil nachgestellte Trennzeichen wie `?` an mehreren Stellen entfernt werden, aber in regulären Ausdrücken für Abfragezeichenfolgen nicht berücksichtigt werden. Die Inhalte beliebiger Dateien können an den Browser zurückgegeben werden. Betroffen sind nur Anwendungen, die den Vite-Entwicklungsserver ausdrücklich für das Netzwerk zugänglich machen (unter Verwendung von `--host` oder der Konfigurationsoption `server.host`). Die Versionen 6.2.3, 6.1.2, 6.0.12, 5.4.15 und 4.5.10 beheben das Problem.
This product uses the NVD API but is not endorsed or certified by the NVD.