Cisco Secure Firewall Management Center Software XPATH Injection Vulnerability
Publication date: Thu, 14 Aug 2025 16:28:00 +0000
Cyber News related to CVE-2025-20218
CVE-2025-20218 - Cisco Secure Firewall Management Center Software XPATH Injection Vulnerability ...
5 months ago
CVE-2025-64027 - Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin ...
2 months ago
CVE-2020-20218 - Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable. ...
3 years ago
CVE-2018-20218 - An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform ...
6 years ago
CVE-2021-20218 - A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest ...
4 years ago
CVE-2019-20218 - selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error. ...
3 years ago
CVE-2022-20218 - In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User ...
2 years ago
CVE-2023-20218 - A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser.
...
2 years ago