CVE-2025-61808
- EPSS -
- Veröffentlicht 09.12.2025 23:41:13
- Zuletzt bearbeitet 10.12.2025 00:16:09
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could lead to arbitrary code execution by a high priviledged attacker. Exploitation of this issue does not ...
CVE-2025-61812
- EPSS -
- Veröffentlicht 09.12.2025 23:41:12
- Zuletzt bearbeitet 10.12.2025 00:16:09
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could allow a high privileged attacker to gain arbitrary code execution. Exploitation of this issue does not require user interac...
CVE-2025-61813
- EPSS -
- Veröffentlicht 09.12.2025 23:41:12
- Zuletzt bearbeitet 10.12.2025 00:16:09
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to acc...
CVE-2025-61821
- EPSS -
- Veröffentlicht 09.12.2025 23:41:11
- Zuletzt bearbeitet 10.12.2025 00:16:10
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to acc...
CVE-2025-64898
- EPSS -
- Veröffentlicht 09.12.2025 23:41:10
- Zuletzt bearbeitet 10.12.2025 00:16:10
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized ...
CVE-2025-61810
- EPSS -
- Veröffentlicht 09.12.2025 23:41:09
- Zuletzt bearbeitet 10.12.2025 00:16:09
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attacker could exploit this...
CVE-2025-61809
- EPSS -
- Veröffentlicht 09.12.2025 23:41:08
- Zuletzt bearbeitet 10.12.2025 00:16:09
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain una...
CVE-2025-61822
- EPSS -
- Veröffentlicht 09.12.2025 23:41:07
- Zuletzt bearbeitet 10.12.2025 00:16:10
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system write. An attacker could exploit this vulnerability to write malicious files to arbitrary loc...
CVE-2025-64897
- EPSS -
- Veröffentlicht 09.12.2025 23:41:07
- Zuletzt bearbeitet 10.12.2025 00:16:10
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access pote...
CVE-2025-61823
- EPSS -
- Veröffentlicht 09.12.2025 23:41:06
- Zuletzt bearbeitet 10.12.2025 00:16:10
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could exploit this vulne...