CVE Vulnerabilities for "product:connect"

Showing 1-10 of 2,316 CVEs (filtered from 316,527 total)

IBM App Connect Enterprise 13.0.1.0 through 13.0.4.2, and 12.0.1.0 through 12.0.12.17 could allow an authenticated user to perform unauthorized actions on customer defined resources due to missing authorization.

MEDIUM 6.3
EPSS 0.0%
10/24/2025
2025

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Forgot Password' endpoint returns distinct JSON responses depending on whether the supplied email address is associated with an existing account. Because the responses differ in the `data.exist` boolean value, an unauthenticated remote attacker can enumerate valid email addresses/accounts on the server. NOTE: D-Link states that a fix is under development.

MEDIUM 6.9
EPSS 0.0%
10/16/2025
2025

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain an observable response discrepancy vulnerability. The application's 'Login' endpoint returns distinct JSON responses depending on whether the supplied username is associated with an existing account. Because the responses differ in the `error.message`string value, an unauthenticated remote attacker can enumerate valid usernames/accounts on the server. NOTE: D-Link states that a fix is under development.

MEDIUM 6.9
EPSS 0.0%
10/16/2025
2025

D-Link Nuclias Connect firmware versions <= 1.3.1.4 contain a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the 'Network' field when editing the configuration, creating a profile, and adding a network. An authenticated attacker can inject arbitrary JavaScript to be executed in the context of other users viewing the profile entry. NOTE: D-Link states that a fix is under development.

MEDIUM 5.1
EPSS 0.0%
10/16/2025
2025

Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction in that a victim must click on a crafted link.

LOW 3.1
EPSS 0.0%
10/14/2025
2025

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Scope is changed.

CRITICAL 9.3
EPSS 0.1%
10/14/2025
2025

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a high-privileged attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that a victim must navigate to a crafted web page. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high. Scope is changed.

HIGH 7.3
EPSS 0.1%
10/14/2025
2025

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

HIGH 7.8
EPSS 0.0%
10/14/2025
2025

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

HIGH 7
EPSS 0.0%
10/14/2025
2025

Memory corruption may occur while processing IOCTL call for DMM/WARPNCC CONFIG request.

MEDIUM 6.6
EPSS 0.0%
10/9/2025
2025
Page 1 of 2