Post

2025-10-08 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2023-6215HP, Inc. - HP Sure Start IFD ProtectionA potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which might allow security bypass, arbitrary code execution, loss of integrity or confidentiality, or denial of service. HP is releasing BIOS updates to mitigate the potential vulnerability.CVSS4.0: 7.2 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: totalHP Sure Start IFD Protection - BIOS Security Updategithub
CVE-2025-0603Callvision Healthcare - Callvision Emergency CodeImproper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection.This issue affects Callvision Emergency Code: before V3.0.CVSS3.1: 9.8 - CRITICAL0Exploitation: noneAutomatable: yesTechnical Impact: totalSQLi in Callvision Healthcare’s Callvision Emergency Codegithub
CVE-2021-22291ABB - EIBPORT V3 KNXABB - EIBPORT V3 KNX GSMImproper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.CVSS4.0: 8.5 - HIGH CVSS3.1: 8 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: totalEIBPORT Reflected XSSgithub
CVE-2025-11292Belkin - F9K1015A weakness has been identified in Belkin F9K1015 1.00.10. Affected is an unknown function of the file /goform/formBSSetSitesurvey. Executing manipulation of the argument wan_ipaddr can lead to command injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.Es wurde eine Schwachstelle in Belkin F9K1015 1.00.10 entdeckt. Davon betroffen ist unbekannter Code der Datei /goform/formBSSetSitesurvey. Durch das Manipulieren des Arguments wan_ipaddr mit unbekannten Daten kann eine command injection-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit ist öffentlich verfügbar und könnte genutzt werden.CVSS4.0: 5.3 - MEDIUM CVSS3.1: 6.3 - MEDIUM0 1 2 3 4Exploitation: pocAutomatable: noTechnical Impact: partialBelkin F9K1015 formBSSetSitesurvey command injectiongithub
This post is licensed under CC BY 4.0 by the author.