7.5

CVSS3.1

CVE-2025-47276 - Actualizer Uses OpenSSL's "-passwd" Function Which Uses SHA512 Under The Hood Instead of Proper Pa…

Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses OpenSSL's "-passwd" function, which uses SHA512 instead of a more suitable password hasher like Yescript/Argon2i. All Actualizer …

πŸ“… Published: May 13, 2025, 3:34 p.m. πŸ”„ Last Modified: May 13, 2025, 7:35 p.m.

6

CVSS4.0

CVE-2025-46721 - nosurf vulnerable to CSRF due to non-functional same-origin request checks

nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls content on the target site, or on a subdomain of the target site (either via XSS, or otherwise) to bypass CSRF checks and issue requests on user's beh…

πŸ“… Published: May 13, 2025, 3:29 p.m. πŸ”„ Last Modified: May 13, 2025, 8:15 p.m.

6.3

CVSS4.0

CVE-2025-31493 - Path traversal of collection names during file system lookup

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` helper or `$kirby->collection()` method with a dynamic collection name (such as a collection name that depends on request or user …

πŸ“… Published: May 13, 2025, 3:24 p.m. πŸ”„ Last Modified: May 13, 2025, 7:35 p.m.

2.3

CVSS4.0

CVE-2025-30207 - Kirby vulnerable to path traversal in the router for PHP's built-in server

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in server. Such setups are commonly only used during local development. Sites that use other server software (such as Apache, nginx or C…

πŸ“… Published: May 13, 2025, 3:20 p.m. πŸ”„ Last Modified: May 13, 2025, 7:37 p.m.

9.8

CVSS3.1

CVE-2025-22462 -

An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.

πŸ“… Published: May 13, 2025, 3:10 p.m. πŸ”„ Last Modified: May 13, 2025, 7:39 p.m.

7.8

CVSS3.1

CVE-2025-22460 -

Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.

πŸ“… Published: May 13, 2025, 3:09 p.m. πŸ”„ Last Modified: May 13, 2025, 7:43 p.m.

6.3

CVSS4.0

CVE-2025-30159 - Kirby vulnerable to path traversal of snippet names in the `snippet()` helper

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `snippet()` helper or `$kirby->snippet()` method with a dynamic snippet name (such as a snippet name that depends on request or user data). Sites…

πŸ“… Published: May 13, 2025, 3:07 p.m. πŸ”„ Last Modified: May 13, 2025, 7:46 p.m.

3.3

CVSS3.1

CVE-2024-12533 -

Improper Check for Unusual or Exceptional Conditions vulnerability in Phoenix SecureCore Technology 4 allows Input Data Manipulation.This issue affects SecureCore Technology 4: from 4.0.1.0 before 4.0.1.1018, from 4.1.0.1 before 4.1.0.573, from 4.2.0.1 before 4.2.0.338, from 4.2.1.1 before 4.2.1.30…

πŸ“… Published: May 13, 2025, 2:56 p.m. πŸ”„ Last Modified: May 13, 2025, 7:35 p.m.

9.6

CVSS3.1

CVE-2025-32756 -

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10, FortiRecorder versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.5, 6.4.0 through 6.4.5, FortiMail versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.4, 7.2.0 through 7.…

πŸ“… Published: May 13, 2025, 2:46 p.m. πŸ”„ Last Modified: May 14, 2025, 8:12 p.m.

5

CVSS3.1

CVE-2025-22859 -

AΒ Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.

πŸ“… Published: May 13, 2025, 2:46 p.m. πŸ”„ Last Modified: May 13, 2025, 7:35 p.m.
Total resulsts: 294006
Page 32 of 29,401
Β« previous page Β» next page
Filters