IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
Publication date: Wed, 28 May 2025 01:12:00 +0000
Cyber News related to CVE-2025-25029
CVE-2025-1095 - IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE). The vulnerability allows any interactively logged in users on the target computer to run commands with full privileges in the ...
2 months ago
CVE-2025-25029 - IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input. ...
4 weeks ago
CVE-2022-25029 - Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-25096. Reason: This candidate is a duplicate of CVE-2022-25096. Notes: All CVE users should reference CVE-2022-25096 instead of this candidate. All references and descriptions in ...
1 year ago
CVE-2018-25029 - The Z-Wave specification requires that S2 security can be downgraded to S0 or other less secure protocols, allowing an attacker within radio range during pairing to downgrade and then exploit a different vulnerability (CVE-2013-20003) to intercept ...
3 years ago
CVE-2019-25029 - In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user ...
4 years ago
CVE-2021-25029 - The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed ...
3 years ago
CVE-2023-25029 - Cross-Site Request Forgery (CSRF) vulnerability in utahta WP Social Bookmarking Light plugin < 2.0.7 versions. ...
2 years ago
CVE-2024-25029 - IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target ...
1 year ago Tenable.com
CVE-2024-7604 - Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This vulnerability allows local attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is required ...
10 months ago