5.5

CVSS3.1

CVE-2025-58335 -

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function

πŸ“… Published: Aug. 28, 2025, 4:48 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 5:32 p.m.

8.1

CVSS3.1

CVE-2025-58334 -

In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

πŸ“… Published: Aug. 28, 2025, 4:48 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

10

CVSS4.0

CVE-2025-57819 - FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue …

πŸ“… Published: Aug. 28, 2025, 4:45 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

4.3

CVSS3.1

CVE-2025-57759 - Contao has improper privilege management for page and article fields

Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in versions 5.3.38 and 5.6.1. There are no wor…

πŸ“… Published: Aug. 28, 2025, 4:32 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:36 p.m.

4.3

CVSS3.1

CVE-2025-57758 - Contao has improper access control in the back end voters

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not relying sole…

πŸ“… Published: Aug. 28, 2025, 4:32 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:37 p.m.

5.3

CVSS3.1

CVE-2025-57757 - Contao discloses information in the news module

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround invol…

πŸ“… Published: Aug. 28, 2025, 4:32 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:38 p.m.

5.3

CVSS3.1

CVE-2025-57756 - Contao discloses sensitive information in the front end search index

Contao is an Open Source CMS. In versions starting from 4.9.14 and prior to 4.13.56, 5.3.38, and 5.6.1, protected content elements that are rendered as fragments are indexed and become publicly available in the front end search. This issue has been patched in versions 4.13.56, 5.3.38, and 5.6.1. A …

πŸ“… Published: Aug. 28, 2025, 4:31 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 5:39 p.m.

6.5

CVSS3.1

CVE-2025-25010 - Kibana privilege escalation via reporting_user role

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_userΒ role which incorrectly has the ability to access all Kibana Spaces.

πŸ“… Published: Aug. 28, 2025, 3:52 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

8.7

CVSS4.0

CVE-2024-13986 - Nagios XI < 2024R1.3.2 Authenticated Arbitrary File Upload Path Traversal RCE

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensions during MIB upload and snapshot rename operati…

πŸ“… Published: Aug. 28, 2025, 3:49 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:47 p.m.

7.5

CVSS3.1

CVE-2025-57767 - Asterisk can crash from a specifically malformed Authorization header in an incoming SIP request

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2, if a SIP request is received with an Authorization header that contains a realm that wasn't in a previous 401 response's WWW-Authenticate header, or an Authorization header with…

πŸ“… Published: Aug. 28, 2025, 3:33 p.m. πŸ”„ Last Modified: Oct. 20, 2025, 5:51 p.m.
Total resulsts: 349182
Page 4099 of 34,919
Β« previous page Β» next page
Filters