Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Justyna Graczyk

#20944of 53,632
11.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2025-20249
5.5
2025-05-07
Cisco · Cisco Catalyst Sd-Wan Manager · CVE-2025-20147
**Name of the Vulnerable Software and Affected Versions** Cisco Catalyst SD-WAN Manager versions (affected versions not specified) **Description** A stored cross-site scripting attack (XSS) could be conducted by an authenticated, remote attacker on an affected system due to improper sanitization of user input to the web-based management interface. The attacker could exploit this by submitting a malicious script through the interface, potentially allowing them to conduct a stored XSS attack on the affected system. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2021-13893
6.4
2021-03-11
Ibm · Ibm Tivoli Netcool/Omnibus Gui · CVE-2021-20336
Name of the Vulnerable Software and Affected Versions: IBM Tivoli Netcool/OMNIbus GUI version 8.1.0 Description: The issue allows users to embed arbitrary JavaScript code in the Web UI, altering the intended functionality and potentially leading to credentials disclosure within a trusted session. This is due to a stored cross-site scripting issue. Recommendations: For IBM Tivoli Netcool/OMNIbus GUI version 8.1.0, consider disabling the Web UI functionality until a patch is available to prevent potential exploitation. Restrict access to the Web UI to minimize the risk of credentials disclosure.