An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.
Publication date: Tue, 15 Apr 2025 21:43:00 +0000
Cyber News related to CVE-2025-27927
CVE-2025-27927 - An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API. ...
5 months ago
CVE-2020-27927 - An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted font file may lead to arbitrary code execution. ...
4 years ago
CVE-2022-27927 - A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number ...
3 years ago
CVE-2023-27927 - An authenticated malicious user could acquire the simple mail transfer protocol (SMTP) Password in cleartext format, despite it being protected and hidden behind asterisks. The attacker could then perform further attacks using the SMTP credentials. ...
2 years ago
CVE-2021-27927 - In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0beta2, the CControllerAuthenticationUpdate controller lacks a CSRF protection mechanism. The code inside this controller calls ...
2 years ago
CVE-2024-27927 - RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network or conduct ...
1 year ago