| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that compromises a user's credentials can gain access to the victim's account, even if the victim has 2FA set up. This is due to 2FA not being enforced if the path parameter is not 44 characters long, which can be bypassed by simply URL encoding a single character in the path. This issue has been patched in version 2025.3.0. |
| A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device.
The vulnerability exists because confidential information is being included in HTTP requests that are exchanged between the user and the device. An attacker could exploit this vulnerability by looking at the raw HTTP requests that are sent to the interface. A successful exploit could allow the attacker to obtain some of the passwords that are configured throughout the interface.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. |
| Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element. |
| Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Transient DOS while decoding message of size that exceeds the available system memory. |
| Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| Memory Corruption in Core during syscall for Sectools Fuse comparison feature. |
| Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16. |
| Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR. |
| Information disclosure in WLAN HAL while handling the WMI state info command. |
| Information disclosure in IOE Firmware while handling WMI command. |
| Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. |
| Cryptographic issue in HLOS during key management. |
| Information disclosure in WLAN HAL while handling command through WMI interfaces. |
| Information disclosure while deriving keys for a session for any Widevine use case. |
| Transient DOS in WLAN Firmware while parsing a BTM request. |
| Transient DOS while processing PDU Release command with a parameter PDU ID out of range. |
| An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP response. |
| An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information. |