NA - CVE-2025-34058 - Hikvision Streaming Media Management Server...
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these...
NA - CVE-2025-34059 - An SQL injection vulnerability exists in the...
An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to...
NA - CVE-2025-34060 - A PHP objection injection vulnerability exists...
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the /get/image/ endpoint. The application passes a...
NA - CVE-2025-34062 - An information disclosure vulnerability exists...
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which...
NA - CVE-2025-34063 - A cryptographic authentication bypass...
A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint....
NA - CVE-2025-34064 - A cloud infrastructure misconfiguration in...
A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An...
NA - CVE-2025-34065 - An authentication bypass vulnerability exists...
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody"...
NA - CVE-2025-34066 - An improper certificate validation...
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and...
NA - CVE-2025-50404 - Intelbras RX1500 Router v2.2.17 and before is...
Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processing the "command" field of the http header,...