Medium - CVE-2025-20285 - A vulnerability in the IP Access Restriction...
A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the...
Medium - CVE-2025-20288 - A vulnerability in the web-based management...
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack...
Critical - CVE-2025-20337 - A vulnerability in a specific API of Cisco ISE...
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker...
NA - CVE-2025-53904 - The Scratch Channel is a news website that is...
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No...
High - CVE-2025-36097 - IBM WebSphere Application Server 9.0 and...
IBM WebSphere Application Server 9.0 and WebSphere Application Server Liberty 17.0.0.3 through 25.0.0.7 are vulnerable to a denial of service, caused by a stack-based overflow. An attacker can...
High - CVE-2025-40777 - If a `named` caching resolver is configured...
If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver,...
NA - CVE-2025-53908 - RomM is a self-hosted rom manager and player....
RomM is a self-hosted rom manager and player. Versions prior to 3.10.3 and 4.0.0-beta.3 have an authenticated path traversal vulnerability in the `/api/raw` endpoint. Anyone running the latest...