CVE Severity Distribution (Last 30 Days)
Found 11 CVEs in the last 30 days.
CVE-2025-27495
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-89
T1190
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on. (ZDI-CAN-25911)
Published: 2025-04-16
CVE-2025-27494
CRITICAL
CVSS: 9.1
EPSS: 0.5%
CWE-20
T1190
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize input for the pubkey endpoint of the REST API. This could allow an authenticated remote administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
Published: 2025-03-11
CVE-2025-27493
HIGH
CVSS: 8.2
EPSS: 0.2%
CWE-20
T1190
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.9), SiPass integrated ACC-AP (All versions < V6.4.9). Affected devices improperly sanitize user input for specific commands on the telnet command line interface. This could allow an authenticated local administrator to escalate privileges by injecting arbitrary commands that are executed with root privileges.
Published: 2025-03-11
CVE-2025-27490
HIGH
CVSS: 7.8
EPSS: 0.6%
CWE-122
CWE-125
T1005
T1203
Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
Published: 2025-04-08
CVE-2025-2749
HIGH
CVSS: 7.2
EPSS: 4.0%
VulnCheck KEV
PoC Available
CWE-22
CWE-434
T1083
T1105
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.
Published: 2025-03-24
CVE-2025-27491
HIGH
CVSS: 7.1
EPSS: 1.5%
CWE-416
T1203
Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network.
Published: 2025-04-08
CVE-2025-27492
HIGH
CVSS: 7.0
EPSS: 0.3%
CWE-362
CWE-416
T1068
T1203
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Secure Channel allows an authorized attacker to elevate privileges locally.
Published: 2025-04-08
CVE-2025-27499
MEDIUM
CVSS: 6.1
EPSS: 0.3%
CWE-79
T1189
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the processa_edicao_socio.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the socio_nome parameter. The injected scripts are stored on the server and executed automatically whenever the affected page is accessed by users, posing a significant security risk. This vulnerability is fixed in 3.2.10.
Published: 2025-03-03
CVE-2025-27496
LOW
CVSS: 3.3
EPSS: 0.1%
CWE-532
T1552
Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Driver would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. Snowflake fixed the issue in version 3.23.1.
Published: 2025-03-13
CVE-2025-27497
UNKNOWN
EPSS: 0.4%
OpenDJ is an LDAPv3 compliant directory service. OpenDJ prior to 4.9.3 contains a denial-of-service (DoS) vulnerability that causes the server to become unresponsive to all LDAP requests without crashing or restarting. This issue occurs when an alias loop exists in the LDAP database. If an ldapsearch request is executed with alias dereferencing set to "always" on this alias entry, the server stops responding to all future requests. Fortunately, the server can be restarted without data corruption. This vulnerability is fixed in 4.9.3.
Published: 2025-03-05
CVE-2025-27498
UNKNOWN
EPSS: 0.1%
aes-gcm is a pure Rust implementation of the AES-GCM. In decrypt_in_place_detached, the decrypted ciphertext (which is the correct ciphertext) is exposed even if the tag is incorrect. This is because in decrypt_inplace in asconcore.rs, tag verification causes an error to be returned with the plaintext contents still in buffer. The vulnerability is fixed in 0.4.3.
Published: 2025-03-03