漏洞描述 用于无线局域网控制器 (WLC) 的 Cisco IOS XE 软件的带外接入点 (AP)映像下载功能中存在一个漏洞,该漏洞可能允许未经身份验证的远程攻击者将任意文件上传到受影响的系统。 此漏洞是由于受影响的系统上存在硬编码的 JSON Web 令牌(JWT) 造成的
相关漏洞推荐 CVE-2001-0537: Cisco IOS HTTP Configuration - Authentication Bypass POC 2025-08-01 | Cisco IOS HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitra... CVE-2023-20198: Cisco IOS XE Web UI - Command Injection POC 2025-08-01 | Cisco IOS XE A vulnerability in the web UI component of Cisco IOS XE Software could allow an unauthenticated, rem... CVE-2025-20188: Cisco IOS XE WLC - Arbitrary File Upload POC 2025-08-01 | Cisco IOS XE WLC A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software... Wordpress Plugin Depicter /wp-admin/admin-ajax.php depicter-lead-list SQL 注入漏洞(CVE-2025-2011) 无POC 2025-09-19 | Wordpress WordPress插件Depicter的滑块和弹出窗口构建器在包括3.6.1版本在内的所有版本中,由于用户提供的参数缺乏足够的转义处理和现有SQL查询的预处理不足,存在通用的SQL注入漏洞。该漏洞可以... Wordpress Plugin Eventin /wp-admin/admin-ajax.php proxy_image 文件读取漏洞(CVE-2025-3419) 无POC 2025-09-19 | Wordpress Event Manager, Events Calendar, Tickets, Registrations – Eventin 是一个用于 WordPress 的插件。该漏洞存在于其 proxy_i...