Show filters
410 Total Results
Displaying 11-20 of 410
Sort by:
Attacker Value
Unknown

CVE-2025-23059

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfully, this vulnerability allows an authenticated remote attacker with high privileges to access and retrieve sensitive data, potentially compromising the integrity and security of the entire system.
0
Attacker Value
Unknown

CVE-2025-23058

Disclosure Date: February 04, 2025 (last updated February 05, 2025)
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.
0
Attacker Value
Unknown

CVE-2025-23057

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.
0
Attacker Value
Unknown

CVE-2025-23056

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.
0
Attacker Value
Unknown

CVE-2025-23055

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.
0
Attacker Value
Unknown

CVE-2025-23054

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an authenticated low privilege operator user to perform operations not allowed by their privilege level. Successful exploitation could allow an attacker to manipulate user generated files, potentially leading to unauthorized changes in critical system configurations.
0
Attacker Value
Unknown

CVE-2025-23053

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A privilege escalation vulnerability exists in the web-based management interface of HPE Aruba Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.
0
Attacker Value
Unknown

CVE-2025-0707

Disclosure Date: January 24, 2025 (last updated February 27, 2025)
A vulnerability was found in Rise Group Rise Mode Temp CPU 2.1. It has been classified as critical. This affects an unknown part in the library CRYPTBASE.dll of the component Startup. The manipulation leads to untrusted search path. The attack needs to be approached locally.
Attacker Value
Unknown

CVE-2025-23623

Disclosure Date: January 16, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mahesh Bisen Contact Form 7 – CCAvenue Add-on allows Reflected XSS.This issue affects Contact Form 7 – CCAvenue Add-on: from n/a through 1.0.
0
Attacker Value
Unknown

CVE-2025-23052

Disclosure Date: January 14, 2025 (last updated February 27, 2025)
Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
0