Post

2025-12-17 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2025-0836Milestone Systems - XProtect VMSMissing Authorization vulnerability in Milestone Systems XProtect VMS allows users with read-only access to Management Server to have full read/write access to MIP Webhooks API.CVSS4.0: 5.3 - MEDIUM CVSS3.1: 6.3 - MEDIUM0 1Exploitation: noneAutomatable: noTechnical Impact: partialXProtect MIP API Missing Authorizationgithub
This post is licensed under CC BY 4.0 by the author.