NA - CVE-2025-23171 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to...
NA - CVE-2025-23172 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can...
NA - CVE-2025-23173 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and...
NA - CVE-2025-24287 - A vulnerability allowing local system users to...
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.
NA - CVE-2025-24288 - The Versa Director software exposes a number of...
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the...
NA - CVE-2025-24291 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability....
NA - CVE-2025-50181 - urllib3 is a user-friendly HTTP client library...
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, it is possible to disable redirects for all requests by instantiating a PoolManager and specifying retries in a way that...
NA - CVE-2025-50182 - urllib3 is a user-friendly HTTP client library...
urllib3 is a user-friendly HTTP client library for Python. Prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the...
NA - CVE-2025-4661 - A path transversal vulnerability in
Brocade...
A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain access to files outside the intended directory potentially leading to the...