7.2

CVSS3.1

CVE-2025-8297 -

Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution

📅 Published: Aug. 12, 2025, 2:37 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

7.2

CVSS3.1

CVE-2025-8296 -

SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution

📅 Published: Aug. 12, 2025, 2:33 p.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

6.3

CVSS3.1

CVE-2024-38805 - iSCSI Remote Memory Corruption and Denial of Service

EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.

📅 Published: Aug. 12, 2025, 2:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2025-22830 - SmiFlash Race Condition Vulnerability

APTIOV contains a vulnerability in BIOS where a skilled user may cause “Race Condition” by local access. A successful exploitation of this vulnerability may lead to resource exhaustion and impact Confidentiality, Integrity, and Availability.

📅 Published: Aug. 12, 2025, 2:02 p.m. 🔄 Last Modified: Oct. 2, 2025, 2:11 p.m.

4.2

CVSS3.1

CVE-2025-22834 - ThirdPartyVideo SetVariable Vulnerability

AMI APTIOV contains a vulnerability in BIOS where a user may cause “Improper Initialization” by local accessing. Successful exploitation of this vulnerability may leave the resource in an unexpected state and potentially impact confidentiality, integrity, and availability.

📅 Published: Aug. 12, 2025, 2:02 p.m. 🔄 Last Modified: Oct. 2, 2025, 2:13 p.m.

6.9

CVSS4.0

CVE-2025-43735 -

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows an remote non-authenticated a…

📅 Published: Aug. 12, 2025, 12:19 p.m. 🔄 Last Modified: Dec. 16, 2025, 4:53 p.m.

7.5

CVSS4.0

CVE-2025-40770 -

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected application uses a monitoring interface that is not operating in a strictly passive mode. This could allow an attacker to interact with the interface, leading to man-in-the-middle attacks.

📅 Published: Aug. 12, 2025, 11:17 a.m. 🔄 Last Modified: Aug. 20, 2025, 8:56 p.m.

7.5

CVSS4.0

CVE-2025-40769 -

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application uses a Content Security Policy that allows unsafe script execution methods. This could allow an attacker to execute unauthorized scripts, potentially leading to cross-s…

📅 Published: Aug. 12, 2025, 11:17 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2025-40768 -

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application exposes an internal service port to be accessible from outside the system. This could allow an unauthorized attacker to access the application.

📅 Published: Aug. 12, 2025, 11:17 a.m. 🔄 Last Modified: Aug. 15, 2025, 6:25 p.m.

8.8

CVSS4.0

CVE-2025-40767 -

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate security controls to enforce isolation. This could allow an attacker to gain elevated access, potentially accessing sensitive ho…

📅 Published: Aug. 12, 2025, 11:17 a.m. 🔄 Last Modified: Aug. 15, 2025, 6:22 p.m.
Total resulsts: 347837
Page 4205 of 34,784
« previous page » next page
Filters