🚨 CVE-2024-43475
Microsoft Windows Admin Center Information Disclosure Vulnerability
🎖@cveNotify
Microsoft Windows Admin Center Information Disclosure Vulnerability
🎖@cveNotify
🚨 CVE-2024-43476
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
🎖@cveNotify
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
🎖@cveNotify
🚨 CVE-2024-38222
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
🎖@cveNotify
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
🎖@cveNotify
🚨 CVE-2024-38183
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
🎖@cveNotify
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
🎖@cveNotify
🚨 CVE-2024-43460
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
🎖@cveNotify
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
🎖@cveNotify
🚨 CVE-2024-43489
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
🎖@cveNotify
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
🎖@cveNotify
🚨 CVE-2024-43496
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
🎖@cveNotify
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
🎖@cveNotify
🚨 CVE-2024-21489
Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.
🎖@cveNotify
Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to missing check if the attribute resolves to the object prototype.
🎖@cveNotify
🚨 CVE-2025-29821
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
🎖@cveNotify
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2025-8361
Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.
This issue affects Config Pages: from 0.0.0 before 2.18.0.
🎖@cveNotify
Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing.
This issue affects Config Pages: from 0.0.0 before 2.18.0.
🎖@cveNotify
Drupal.org
Config Pages - Moderately critical - Access bypass - SA-CONTRIB-2025-093
This module enables you to access an edit page for a config page. The module doesn't sufficiently check the access permissions (hook_ENTITY_TYPE_access() wasn't taken into account). This vulnerability is mitigated by the fact that an attacker must have a…
🚨 CVE-2025-6999
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack.
WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.
🎖@cveNotify
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack.
WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.
🎖@cveNotify
🚨 CVE-2025-9242
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
🎖@cveNotify
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
🎖@cveNotify
🚨 CVE-2025-1549
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileges on the Windows system. This vulnerability is an additional unmitigated attack path for CVE-2024-4944.
This vulnerability is resolved in the Mobile VPN with SSL client for Windows version 12.11.5
🎖@cveNotify
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileges on the Windows system. This vulnerability is an additional unmitigated attack path for CVE-2024-4944.
This vulnerability is resolved in the Mobile VPN with SSL client for Windows version 12.11.5
🎖@cveNotify
🚨 CVE-2025-11838
A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.
🎖@cveNotify
A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.
🎖@cveNotify
🚨 CVE-2025-12026
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
🎖@cveNotify
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
🎖@cveNotify
🚨 CVE-2025-12195
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.
🎖@cveNotify
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.
🎖@cveNotify