Common Vulnerabilities and Exposures (CVE)

CVE-2025-46408

Sep 17, 2025 13:40:32 UTC

An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain valid...

CVE-2025-9818

Sep 17, 2025 13:40:05 UTC

A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided by OMRON SOCIAL SOLUTIONS Co., Ltd., where the executable file paths of Windows services are not enclosed in quotation m...

CVE-2025-43805

Sep 17, 2025 13:39:36 UTC

Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not perform an authorization check when users attempt to view a display page templat...

CVE-2025-37131

Sep 17, 2025 13:39:02 UTC

A vulnerability in EdgeConnect SD-WAN ECOS could allow an authenticated remote threat actor with admin privileges to access sensitive unauthorized system files. Under certain conditions, this could lead to exposure and exfiltration of sensi...

CVE-2025-43357

Sep 17, 2025 13:38:36 UTC

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26, iOS 26 and iPadOS 26. An app may be able to fingerprint the user.

CVE-2025-37126

Sep 17, 2025 13:38:22 UTC

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability wil...

CVE-2025-55075

Sep 17, 2025 13:38:05 UTC

Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, SSH may be enabled by a remote authenticated attacker.

CVE-2025-37124

Sep 17, 2025 13:37:35 UTC

A vulnerability in the HPE Aruba Networking SD-WAN Gateways could allow an unauthenticated remote attacker to bypass firewall protections. Successful exploitation could allow an attacker to route potentially harmful traffic through the inte...

CVE-2025-43372

Sep 17, 2025 13:37:21 UTC

The issue was addressed with improved input validation. This issue is fixed in tvOS 26, watchOS 26, visionOS 26, macOS Tahoe 26, iOS 26 and iPadOS 26. Processing a maliciously crafted media file may lead to unexpected app termination or cor...

CVE-2025-37123

Sep 17, 2025 13:36:54 UTC

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to ...

CVE-2022-43023

Sep 17, 2025 13:34:38 UTC

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

CVE-2025-37125

Sep 17, 2025 13:34:28 UTC

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly

CVE-2025-58116

Sep 17, 2025 13:34:00 UTC

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated att...

CVE-2025-10589

Sep 17, 2025 13:28:57 UTC

The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.

CVE-2022-43021

Sep 17, 2025 13:27:54 UTC

OpenCATS v0.9.6 was discovered to contain a SQL injection vulnerability via the entriesPerPage variable.