5.3

CVSS4.0

CVE-2025-3089 - Broken Access Control in ServiceNow AI Platform

ServiceNow has addressed a Broken Access Control vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could allow a low privileged user to bypass access controls and perform a limited set of actions typically reserved for higher privileged users, potentially leading t…

πŸ“… Published: Aug. 12, 2025, 4:06 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2025-55164 - content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE

content-security-policy-parser parses content security policy directives. A prototype pollution vulnerability exists in versions 0.5.0 and earlier, wherein if a policy name is called __proto__, one can override the Object prototype. This issue has been patched in version 0.6.0. A workaround involve…

πŸ“… Published: Aug. 12, 2025, 4:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2025-5187 - Nodes can delete themselves by adding an OwnerReference

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted,…

πŸ“… Published: Aug. 12, 2025, 4 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-55010 - Kanboard Authenticated Admin Remote Code Execution via Unsafe Deserialization of Events

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users the ability to instantiate arbitrary php objects by modifying the event["data"] field in the projec…

πŸ“… Published: Aug. 12, 2025, 3:57 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 5:28 p.m.

6.4

CVSS3.1

CVE-2025-55011 - Kanboard Path Traversal in File Write via Task File Upload Api

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does not validate whether the task_id parameter is a valid task id, nor does it check for path traversal. As a result, a malicious actor could write a file a…

πŸ“… Published: Aug. 12, 2025, 3:57 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 5:15 p.m.

6.9

CVSS4.0

CVE-2025-54864 - Hydra missing authentication when triggering evaluations through GitHub and Gitea plugins

Hydra is a continuous integration service for Nix based projects. Prior to commit f7bda02, /api/push-github and /api/push-gitea are called by the corresponding forge without HTTP Basic authentication. Both forges do however feature HMAC signing with a secret key. Triggering an evaluation can be ver…

πŸ“… Published: Aug. 12, 2025, 3:48 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 2:58 p.m.

7.1

CVSS4.0

CVE-2025-54800 - Hydra persistent XSS in build metrics

Hydra is a continuous integration service for Nix based projects. Prior to commit dea1e16, a malicious package can introduce arbitrary JavaScript code into the Hydra database that is automatically evaluated in a client's browser when anyone visits the build page. This could be done by a third-party…

πŸ“… Published: Aug. 12, 2025, 3:47 p.m. πŸ”„ Last Modified: Sept. 22, 2025, 2:57 p.m.

4.3

CVSS3.1

CVE-2025-8452 - Unauthenticated leak of sensitive information affecting multiple models from Brother Industries, Lt…

By using the "uscan" protocol provided by the eSCL specification, an attacker can discover the serial number of multi-function printers that implement the Brother-provided firmware. This serial number can, in turn, can be leveraged by the flaw described by CVE-2024-51978 to calculate the default ad…

πŸ“… Published: Aug. 12, 2025, 3:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-5468 -

Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to re…

πŸ“… Published: Aug. 12, 2025, 3:05 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 6:17 p.m.

4.9

CVSS3.1

CVE-2025-5466 -

XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial of…

πŸ“… Published: Aug. 12, 2025, 3 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 6:18 p.m.
Total resulsts: 347841
Page 4204 of 34,785
Β« previous page Β» next page
Filters