Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1.
Publication date: Fri, 10 Oct 2025 22:24:00 +0000
Cyber News related to CVE-2025-9549
CVE-2025-9549 - Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 before 2.0.10, from 3.0.0 before 3.0.1. ...
20 hours ago
CVE-2019-9549 - An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?moduser&actaddnew URI, as demonstrated by adding a level1 account, a similar issue to CVE-2018-18935. ...
6 years ago
CVE-2018-9549 - In lppTransposer of lpp_tran.cpp there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: ...
5 years ago
CVE-2015-9549 - A reflected Cross-site Scripting (XSS) vulnerability exists in OcPortal 9.0.20 via the OCF_EMOTICON_CELL.tpl FIELD_NAME field to data/emoticons.php. ...
4 years ago
CVE-2020-9549 - In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document. ...
3 years ago
CVE-2024-33225 - An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests. ...
1 year ago
CVE-2024-9549 - A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This issue affects the function formEasySetupWizard/formEasySetupWizard2 of the file /goform/formEasySetupWizard. The manipulation of the argument curTime leads to ...
1 year ago