NA - CVE-2025-34062 - An information disclosure vulnerability exists...
An information disclosure vulnerability exists in OneLogin AD Connector versions prior to 6.1.5 via the /api/adc/v4/configuration endpoint. An attacker with access to a valid directory_token—which...
NA - CVE-2025-34063 - A cryptographic authentication bypass...
A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure of a tenant’s SSO JWT signing key via the /api/adc/v4/configuration endpoint....
NA - CVE-2025-34064 - A cloud infrastructure misconfiguration in...
A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket (onelogin-adc-logs-production) without validating bucket ownership. An...
NA - CVE-2025-34065 - An authentication bypass vulnerability exists...
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody"...
NA - CVE-2025-34066 - An improper certificate validation...
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and...
NA - CVE-2025-50404 - Intelbras RX1500 Router v2.2.17 and before is...
Intelbras RX1500 Router v2.2.17 and before is vulnerable to Integer Overflow. The websReadEvent function incorrectly uses the int type when processing the "command" field of the http header,...
NA - CVE-2025-50405 - Intelbras RX1500 Router v2.2.17 and before is...
Intelbras RX1500 Router v2.2.17 and before is vulnerable to Incorrect Access Control in the FirmwareUpload function and GetFirmwareValidation function.
NA - CVE-2025-53099 - Sentry is a developer-first error tracking and...
Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take advantage of a...
High - CVE-2025-6957 - A vulnerability was found in Campcodes Employee...
A vulnerability was found in Campcodes Employee Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /process/eprocess.php. The manipulation...